Kimsuky__2021__Inquest_Kimsuky-Espionage-Campaign_08-23-2021.pdf
ID: a335247e-a6e1-43c4-af2e-486607a2b528
STIX ID: report--a335247e-a6e1-43c4-af2e-486607a2b528
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2021-09-07
Last Modified Date: 2021-09-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Kimsuky Espionage Campaign — analysis shows a malicious JavaScript disguised as a PDF that decodes embedded Base64 payloads to drop and execute an UPX-packed DLL which unpacks into a Kimsuky spyware DLL. The malware searches for document filetypes (including on USB drives), implements keylogging and persistence via regsvr32/RunOnce, and the report provides file hashes and a network IoC for detection and hunting.
