20231101_Kimsuky_OP.-Covert-Stalker-EN.pdf
ID: 31f3c59e-dfe1-47db-b02d-0d937bad2560
STIX ID: report--31f3c59e-dfe1-47db-b02d-0d937bad2560
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2023-11-06
Last Modified Date: 2023-11-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
AhnLab's "Operation Covert Stalker" report attributes a 17‑month targeted campaign to the Kimsuky organization that focused on North Korea/policy-related targets. The adversary exploited RDP (CVE-2019-0708) and vulnerable web applications to deploy web shells (Green Dinosaur, Webadmin), build PHP-based C2/phishing infrastructure, and distribute malware families including RATs, infostealers, EternalBlue components, and BlackBit ransomware; the report provides extensive IoCs (URLs, IPs, hashes), behavioral logs, and examples of phishing proxies and weaponized attachments used to exfiltrate credentials and data.
