Kimsuky__2021__AhnLab_Analysis-Report-of-Kimsuky-Group_01-05-2021.pdf
ID: 025e0975-5ca6-4226-ac6b-2f864346d06b
STIX ID: report--025e0975-5ca6-4226-ac6b-2f864346d06b
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2022-01-03
Last Modified Date: 2022-01-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This AhnLab analysis details Kimsuky APT operations using AppleSeed and PebbleDash delivered via spear‑phishing (WSF/JS/PIF) to deploy backdoors, downloaders and remote access tools; it documents command-and-control methods (HTTP, SMTP/IMAP), info‑stealing and persistence behaviors, privilege‑escalation methods (UAC bypass, CVE-2021-1675/34527 usage), a large set of IOCs (hashes, domains, IPs, file paths), and post‑infection tooling (Meterpreter, HVNC/TightVNC, Mimikatz) along with detection notes and recommended countermeasures.
