BabyShark is a VBScript-based persistent loader targeting Windows systems and associated with the North Korea-linked Kimsuky threat ecosystem. It operates through sequential stages that retrieve and execute additional scripts or payloads, providing a foothold for reconnaissance and remote administration. BabyShark has been associated with campaigns targeting U.S. national security think tanks and South Korean entities, including COVID-19-themed malicious email campaigns in February 2020. The North Korea-aligned actor TA406 had access to BabyShark by early 2019, although it was not the malware’s original user.
BabyShark enumerates running processes, identifies the current user, and collects local network configuration information using native Windows commands. It uses the Windows HTML Application Host to download and execute remote applications and can decode downloaded files before execution. Its PowerShell-based remote administration functionality can implement keyloggers written in PowerShell or C#. Collected data can be encoded with the Windows certificate utility before exfiltration.
Persistence mechanisms include scheduled tasks and registry modifications. BabyShark also modifies Microsoft Word and Excel security settings to enable future macros, weakening application-level protections and facilitating continued execution. It removes files associated with secondary-payload execution to reduce residual artifacts. Its lightweight, staged architecture allows operators to extend functionality through remotely supplied scripts and payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2024-1708 (CVSS:8.4) is a path traversal vulnerability that can allow an attacker to execute code remotely on the ScreenConnect server. Together, CVE-2024-1709 and CVE-2024-1708 can allow a threat actor to perform remote code execution post authentication. | The Kroll CTI team observed a campaign using a new malware that appears to be very similar to BABYSHARK... Kroll assessed it is likely that this is a variant of the BABYSHARK malware due to code and behavioral similarities.
Two critical vulnerabilities, tracked as CVE-2024-1708 and CVE-2024-1709, were recently addressed in ConnectWise ScreenConnect and have been exploited by many threat actors due to its ease of exploitability. CVE-2024-1709 (CVSS:10) can allow for authentication bypass due to insufficient path filtering. | The Kroll CTI team observed a campaign using a new malware that appears to be very similar to BABYSHARK... Kroll assessed it is likely that this is a variant of the BABYSHARK malware due to code and behavioral similarities.
"We have not observed an in-the-wild case yet, but we did find a PHP sample exploiting CVE-2018-8174 (Windows VBScript Engine Remote Code Execution Vulnerability) on the BabyShark C2 server, and this suggests that the threat actor may be leveraging this vulnerability to make a target load BabyShark’s first stage HTA via a watering hole attack or a malicious URL in a spearphishing email."
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VelvetCake’s architecture of combining a minimalist client with server-side logic mirrors the design philosophy of related Kimsuky toolsets, including the FlowerPower, GitPower, and BabyShark families, where lightweight loaders execute server-side commands and push results back to remote infrastructure.
The spam campaigns were used to distribute BabyShark implants, often associated with the cyber operations of North Korea.
Adversary Malware Target • TroiBomb • RoastMe • JamBog (AppleSeed) • BabyShark • DongMulRAT (WildCommand)
Adversary Malware Target • TroiBomb • RoastMe • JamBog (AppleSeed) • BabyShark • DongMulRAT (WildCommand)
Adversary Malware Target • TroiBomb • RoastMe • JamBog (AppleSeed) • BabyShark • DongMulRAT (WildCommand)
These same techniques have also been associated with threat groups like APT32 and are leveraged by malware families such as AgentTesla and BabyShark.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes malware and threat actors establishing persistence by adding values under Registry Run keys such as HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run, and by placing shortcuts or files in Startup folders.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
The content is a long ATT&CK-style listing of malware and threat groups that 'decrypt', 'decode', 'deobfuscate', 'unpack', or 'decompress' payloads, strings, configuration data, shellcode, and files prior to execution or use.
APT29 has use mshta to execute malicious scripts on a compromised host... APT32 has used mshta.exe for code execution... APT38 has used a renamed version of mshta.exe to execute malicious HTML files... FIN7 has used mshta.exe to execute VBScript to execute malicious code on victim systems.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
129 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
69 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related Kimsuky toolset referenced as a lightweight loader that executes server-side commands and returns results to remote infrastructure.
Implant delivered via COVID-themed spam targeting South Korean entities.
A malware/campaign family discussed as historically linked to KimJongRAT and attributed in the report to Kimsuky.
Malware payload referenced as being delivered after QR-code (“quishing”) spear-phishing; used to establish access after credential harvesting and support follow-on activity (persistence/lateral movement/exfiltration) in the described Kimsuky campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.