logo

(3) Kimsuky is targeting an arms manufacturer in Europe. | LinkedIn

ID: 18851919-2acd-4608-978a-43b36c07bb1e

STIX ID: report--18851919-2acd-4608-978a-43b36c07bb1e

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2024-06-25

Last Modified Date: 2024-06-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
On 16 May 2024 researchers attributed a spear-phishing campaign to the North Korean APT Kimsuky targeting a Western European weapons manufacturer; the attacker delivered a malicious .jse attachment that decodes a benign PDF as a visual lure and a double-base64 encoded x64 DLL espionage payload which establishes persistence (service "CacheDB" and Run registry), communicates with C2 infrastructure (notably download.uberlingen.com -> 94.131.120.80 and related hosts/IPs), and supports file enumeration, process listing, screenshots, remote execution and data exfiltration. The report includes file hashes, network indicators, a YARA rule, decrypted runtime strings and recommended IoCs for detection and hunting.