Kimsuky LNK Malware Utilizing Multi-Channel C2 Infrastructure
Score: 8/10

Kimsuky LNK Malware Utilizing Multi-Channel C2 Infrastructure

The Kimsuky group is deploying a new multi-stage LNK malware campaign targeting South Korean financial sectors using GitHub, Dropbox, and WordPress as functional C2 channels.

Executive Summary

A new malware campaign attributed to the Kimsuky threat actor group has been identified, characterized by the use of malicious LNK (shortcut) files disguised as legitimate South Korean financial documents, such as asset management reports and insurance claims. The attack utilizes a highly modular Command and Control (C2) infrastructure that separates functions—instruction delivery, infection notification, and data exfiltration—across different legitimate cloud services including GitHub, WordPress, and Dropbox.

The attack chain progresses through multiple stages, beginning with a Base64-encoded LNK file that leverages system tools like `certutil.exe` to decode and execute secondary BAT scripts. A notable feature is the use of the 'Dead Drop' technique, where the malware retrieves commands from public GitHub repositories to evade network-based detection. The campaign prioritizes stealth by using Living-off-the-Land Binaries (LOLBins) and legitimate utilities like NirCmd to maintain persistence via Scheduled Tasks without leaving traditional malicious artifacts on the disk.

This activity is significant due to its targeted nature, using the victim's `MachineGuid` to provide host-specific instructions. This allows attackers to selectively escalate infection stages from reconnaissance to remote access (Reverse Tunneling) based on the profile of the compromised machine. The reliance on trusted domains makes traditional domain-level blocking difficult for defenders.

Key Details

Threat Name

Kimsuky LNK Malware Campaign

Affects

GitLab, Google Chrome, MS Word, Windows

Adversary

Kimsuky

Malware/Tools

Trojan.Agent.LNK.Gen, Trojan.BAT.Agent

Report Score

8out of 10
Quality Score
Good
IOC Quality7
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources