216.73.216.6

Warning Against Distribution of Malware Disguised as Research Papers

· Published 18/06/2025 17:46 · Modified 23/06/2025 19:57

Export JSON

Essential information

Published
18/06/2025 17:46
Modified
23/06/2025 19:57
Tags
2025-06-18 anydesk apt dropbox hwp ole phishing remote access social engineering
Related entities
3 observables, 1 intrusion sets (apt), 14 techniques (mitre)

Description

The Kimsuky group has launched a sophisticated attack disguised as a request for paper review from a professor. The attack involves a password-protected document with a malicious object, which creates six files upon opening. When executed, these files perform various malicious activities, including collecting system information, downloading additional files, and establishing through . The threat actors use legitimate software and cloud storage services like as part of their attack infrastructure. The malware hides its presence by concealing 's interface, making detection difficult for users. This case highlights the evolving tactics of groups and the importance of cautious handling of files from unknown sources.