Kimsuky APT-C-55 Attack Chain Analysis
Score: 8/10

Kimsuky APT-C-55 Attack Chain Analysis

Kimsuky (APT-C-55) utilizes multi-stage PowerShell and C# malware delivered via disguised installers to target South Korean institutions for intelligence theft.

Executive Summary

Kimsuky, also known as APT-C-55 and BabyShark, is a prolific threat actor primarily targeting South Korean think tanks, government entities, and academic institutions. Recent analysis by 360 Advanced Threat Institute reveals an evolved attack chain that leverages deceptive installation packages (e.g., OrionQuests-Setup.exe) to deliver a modular C# backdoor framework named Stella_Gary.

The technical workflow begins with a .NET-based installer that drops a malicious LNK file. This LNK executes a PowerShell script that performs extensive anti-analysis checks against 42 different security tools and virtualization environments. Upon successful environment validation, the malware achieves persistence via scheduled tasks masquerading as 'Google Chrome Update' and reflectively loads additional .NET modules directly into memory to evade disk-based detection.

This campaign demonstrates Kimsuky's increasing sophistication, particularly in its use of file-type masquerading (e.g., hiding payloads behind RTF headers), JavaScript-based anti-bot bypasses on C2 infrastructure, and modular plugin architectures. Organizations in targeted sectors should prioritize monitoring for anomalous PowerShell execution and unauthorized scheduled task creation.

Key Details

Threat Name

Kimsuky APT-C-55

Affects

Government and diplomatic organisations, Think tanks, News media organisations, Educational and academic institutions

Adversary

Kimsuky Other Adversaries and Aliases: APT-C-55; BabyShark

Malware/Tools

PowerShell, Stella_Gary, cscript.exe, OrionQuests-Setup.exe

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance4
Enterprise Relevance8
Clarity & Structure9
Technical Depth8

Sources