Executive Summary
Kimsuky, also known as APT-C-55 and BabyShark, is a prolific threat actor primarily targeting South Korean think tanks, government entities, and academic institutions. Recent analysis by 360 Advanced Threat Institute reveals an evolved attack chain that leverages deceptive installation packages (e.g., OrionQuests-Setup.exe) to deliver a modular C# backdoor framework named Stella_Gary.
The technical workflow begins with a .NET-based installer that drops a malicious LNK file. This LNK executes a PowerShell script that performs extensive anti-analysis checks against 42 different security tools and virtualization environments. Upon successful environment validation, the malware achieves persistence via scheduled tasks masquerading as 'Google Chrome Update' and reflectively loads additional .NET modules directly into memory to evade disk-based detection.
This campaign demonstrates Kimsuky's increasing sophistication, particularly in its use of file-type masquerading (e.g., hiding payloads behind RTF headers), JavaScript-based anti-bot bypasses on C2 infrastructure, and modular plugin architectures. Organizations in targeted sectors should prioritize monitoring for anomalous PowerShell execution and unauthorized scheduled task creation.
Key Details
Threat Name
Kimsuky APT-C-55
Affects
Government and diplomatic organisations, Think tanks, News media organisations, Educational and academic institutions
Adversary
Kimsuky Other Adversaries and Aliases: APT-C-55; BabyShark
MITRE Techniques
Malware/Tools
PowerShell, Stella_Gary, cscript.exe, OrionQuests-Setup.exe
