VB2021 paper: Operation Newton: Hi Kimsuky? Did an Apple(Seed) really fall on Newton’s head?
ID: 8d67cdca-6025-44ef-9e9f-2566c719f180
STIX ID: report--8d67cdca-6025-44ef-9e9f-2566c719f180
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2021-09-30
Last Modified Date: 2021-09-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This VB2021 report analyzes 'Operation Newton', a November 2020 Kimsuky APT campaign that targeted scientific and engineering researchers using webmail JavaScript injection and spear-phishing to harvest credentials, deploy the AppleSeed backdoor and Meterpreter payloads, install web shells on Linux/Windows servers, move laterally via stolen VPN and server accounts, and exfiltrate research data via FTP and obfuscated channels; the paper provides full-chain TTPs, malware decoding routines (double XOR), C2 behaviors, IOCs, and a discovered command-injection OPSEC failure on the AppleSeed server that aided tracking.
