logo

Kimsuky__2020__The_North_Korean_Kimsuky_APT_keeps_threatening_South_Korea_evolving_its_TTPs.pdf

ID: 39f32a97-ec98-47e2-8fae-fcccd79283a6

STIX ID: report--39f32a97-ec98-47e2-8fae-fcccd79283a6

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2020-03-04

Last Modified Date: 2020-03-04

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This technical report analyzes a Kimsuky APT malware campaign observed in early 2020: an initial .scr loader drops a DLL (AutoUpdate.dll), achieves persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\WindowsDefender, injects payloads into explorer.exe, and periodically phones home to a C2 (suzuki.datastore.pe.hu). The analysis includes file hashes, network captures, YARA rules, and discusses AV evasion and string decryption routines, concluding attribution to the North Korean Kimsuky actor based on TTP overlap.