North Korea-linked Kimsuky has been tied to a series of phishing campaigns that delivered malware through files disguised as PDFs, resumes, questionnaires, and North Korea-related consultation documents. Across the observed intrusions, victims were lured into opening password-protected archives, enabling Office macros, or executing VBS and CHM files, after which the malware launched follow-on payloads through tools such as wscript.exe, mshta.exe, regsvr32.exe, and PowerShell. The implants opened decoy documents to reduce suspicion, established persistence with scheduled tasks, Startup-folder copies, or HKCU\Run entries, and contacted attacker-controlled infrastructure including kro.kr, webcindario, and PHP-based command-and-control endpoints.
The recovered payloads show Kimsuky broadening from simple downloaders into multi-stage surveillance and theft malware. Reported capabilities include host reconnaissance, browser and email data theft, crypto-wallet artifact collection, file upload and download, keylogging, clipboard capture, active-window monitoring, and registry changes that weaken Microsoft Office security settings. Researchers also linked newer operations to a wider infrastructure ecosystem, including SharpExt-related panels and a compromised site used to deliver browser-extension malware, while one later campaign exfiltrated stolen victim data through the GitHub API instead of FTP, indicating continued adaptation in both delivery and collection methods.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
ASEC said its RAPIT system recorded a server response containing additional attacker commands in the North Korea-themed VBS phishing campaign. The response wrote Base64 data to a temporary file, decoded it with certutil into mscornet.vbs, and deleted the temporary file.
A recovered Hangul Word Processor lure titled "The Burden of the Unintended.hwp" was created and later tied to older Kimsuky operations. Walmart Global Tech reported the file's creation date as 2022-02-24.
K7 Labs described Kimsuky, also known as Black Banshee, as a North Korean state-sponsored APT group that has been active since at least 2012.
K7 Labs analyzed a recent Kimsuky infection chain delivered through a ZIP archive containing a VBScript, PowerShell loader, and two encoded log files. The decoded payloads performed browser and wallet data theft, reconnaissance, persistence, file transfer, keylogging, clipboard monitoring, and active window logging.
ASEC identified an email campaign distributing a password-protected Word document named "[붙임] 약력 양식.doc" that impersonated a professor. After macro execution, the malware downloaded additional scripts and used the GitHub API instead of FTP to upload browser-stolen victim information to a repository that already contained suspected victim data.
Walmart Global Tech expanded prior reporting on Kimsuky's SharpExt operations by identifying additional domains, panel structures, and a compromised website linked to the campaigns. The analysis also connected this infrastructure to older malicious-document operations and victim targeting in the United States, Europe, and South Korea.
ASEC identified a phishing campaign distributing a password-protected archive containing a malicious CHM file disguised as an interview questionnaire. The CHM decoded a VBS payload, added persistence through the HKCU Run key, and led to PowerShell-based keylogging, clipboard theft, and exfiltration.
ASEC reported continuous distribution of malicious Word documents themed around North Korea-related topics. In one observed flow, the attacker first sent a benign consultation request and only provided a malicious download link after the recipient replied.
Walmart Global Tech reported that the compromised website nuclearpolicy101.org was updated earlier in the year to deliver browser extension code tied to the same Kimsuky command-and-control endpoint. The site had already been used by the group for over a year.
ASEC identified a phishing campaign distributing a malicious VBS script named "2022 이력서 양식.vbs" inside a compressed attachment. The malware collected host information, exfiltrated it to webcindario URLs, opened a decoy HWP file, and established persistence via a scheduled task and Startup folder.
ASEC reported discovering APT attacks targeting certain Korean companies using a VBS file disguised as a PDF. The activity was assessed with moderate confidence as likely conducted by Kimsuky based on tradecraft and infrastructure overlaps.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
labs.k7computing.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcemedium.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.