Executive Summary
A new malware campaign attributed to the Kimsuky threat actor group has been identified, characterized by the use of malicious LNK (shortcut) files disguised as legitimate South Korean financial documents, such as asset management reports and insurance claims. The attack utilizes a highly modular Command and Control (C2) infrastructure that separates functions—instruction delivery, infection notification, and data exfiltration—across different legitimate cloud services including GitHub, WordPress, and Dropbox.
The attack chain progresses through multiple stages, beginning with a Base64-encoded LNK file that leverages system tools like `certutil.exe` to decode and execute secondary BAT scripts. A notable feature is the use of the 'Dead Drop' technique, where the malware retrieves commands from public GitHub repositories to evade network-based detection. The campaign prioritizes stealth by using Living-off-the-Land Binaries (LOLBins) and legitimate utilities like NirCmd to maintain persistence via Scheduled Tasks without leaving traditional malicious artifacts on the disk.
This activity is significant due to its targeted nature, using the victim's `MachineGuid` to provide host-specific instructions. This allows attackers to selectively escalate infection stages from reconnaissance to remote access (Reverse Tunneling) based on the profile of the compromised machine. The reliance on trusted domains makes traditional domain-level blocking difficult for defenders.
