Summary:
Kimsuky is a suspected North Korean APT organization that primarily targets businesses and people on a global scale. The gang, which has been active at least since 2012, frequently uses targeted phishing and social engineering methods to gather intelligence and gain unauthorized access to private data, serving the objectives of the North Korean government. So as to further attacks, Kimsuky has constantly distributed custom malware as a part of reconnaissance missions. ReconShark malware communication by the organization via Office documents with macro capability has just become public. The campaign evolution towards the use of a RandomQuery malware version with only the aim of file enumeration and data exfiltration. This contrasts with previously discovered RandomQuery versions that offer a larger range of capabilities, like keylogging and the execution of additional malware.[/subscribe_to_unlock_form]
Summary:
Kimsuky is a suspected North Korean APT organization that primarily targets businesses and people on a global scale. The gang, which has been active at least since 2012, frequently uses targeted phishing and social engineering methods to gather intelligence and gain unauthorized access to private data, serving the objectives of the North Korean government. So as to further attacks, Kimsuky has constantly distributed custom malware as a part of reconnaissance missions. ReconShark malware communication by the organization via Office documents with macro capability has just become public. The campaign evolution towards the use of a RandomQuery malware version with only the aim of file enumeration and data exfiltration. This contrasts with previously discovered RandomQuery versions that offer a larger range of capabilities, like keylogging and the execution of additional malware.[emaillocker id="1283"]
Kimsuky spreads RandomQuery using phishing emails that have been carefully designed. A typical Kimsuky phishing technique, the phishing emails are sent to targets from an account registered with the South Korean email provider Daum. The phishing emails sent by Kimsuky, the people who receive them, usually in the Korean language, are requested to review a paper that is attached. The email claims that the paper was written by Lee Kwang-Baek, who is reported to be the CEO of Daily NK.. DPRK threat actors seeking to appear legitimate often mimic them. A password-protected archive contains the CHM file that is connected to this article. In keeping with the campaign's targeted plan of attack, The CHM file includes a malicious Shortcut object that runs upon the Click event. The creates a file with Base-64 encoding, like mini.dat. after creating a VB script by decoding the file with the "certutil" utility, then saving the script in a separate file. Establishes persistence by modifying the Run registry entry so that the newly produced VB script is run when the system starts and Then C2 server URL receives an HTTP GET request from the VB script.
The RandomQuery variation distributed by Kimsuky initially sets up the Internet Explorer browser by altering the registry. The malware refers to these three types of information as Basic System, Specific Folder, and Process List, and RandomQuery continues on collecting and exfiltrating them. The malware first gathers system and hardware information then computer name, processor speed, OS version, and the amount of physical memory available to the system. RandomQuery refers to this information as Basic System information. Then sends an HTTP POST request containing the information to a C2 server URL Base64-encoding the collected data.
Kimsuky and its constantly improving attack toolkit. These cases show how North Korean threat groups' missions are constantly evolving to include not only political espionage but also sabotage and financial threats.
Threat Profile:

References:
The following reports contain further technical details:
https://www.sentinelone.com/labs/kimsuky-ongoing-campaign-using-tailored-reconnaissance-toolkit/
[/emaillocker]