logo

Kimsuky__2021__Inquest_Kimsuky-Espionage-Campaign_08-23-2021.pdf

ID: a335247e-a6e1-43c4-af2e-486607a2b528

STIX ID: report--a335247e-a6e1-43c4-af2e-486607a2b528

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2021-09-07

Last Modified Date: 2021-09-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kimsuky Espionage Campaign — analysis shows a malicious JavaScript disguised as a PDF that decodes embedded Base64 payloads to drop and execute an UPX-packed DLL which unpacks into a Kimsuky spyware DLL. The malware searches for document filetypes (including on USB drives), implements keylogging and persistence via regsvr32/RunOnce, and the report provides file hashes and a network IoC for detection and hunting.