216.73.216.226

Kimsuky: A Gift That Keeps on Giving

· Published 20/09/2024 11:39 · Modified 20/09/2024 12:06

Export JSON

Essential information

Published
20/09/2024 11:39
Modified
20/09/2024 12:06
Tags
2024-09-20 espionage kimsuky north korea
Related entities
2 observables, 1 intrusion sets (apt), 20 techniques (mitre)

Description

This analysis details a sophisticated cyber attack attributed to the North Korean-linked APT group. The attack begins with an LNK file, leading to the execution of obfuscated VBS scripts. These scripts create scheduled tasks, modify registry keys for persistence, and establish communication with a command and control (C2) server. The malware employs various evasion techniques, including Base64 encoding and Caesar Cipher obfuscation. The ultimate goal appears to be maintaining long-term access to the victim's machine for activities. The report also includes a personal anecdote of the analyst's brief interaction with the C2 server, receiving a single command after hours of waiting.

External references