logo

Kimsuky Threat Research Report-2

ID: e56219d4-6088-4b9c-883c-372493ed2346

STIX ID: report--e56219d4-6088-4b9c-883c-372493ed2346

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2025-07-25

Last Modified Date: 2025-07-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report from Aryaka Threat Research Lab documents a multi-stage Kimsuky APT cyber-espionage campaign targeting South Korean entities, detailing an infection chain that begins with malicious LNK/HTA files and uses obfuscated VBScript/PowerShell, persistence, anti-VM checks, reflective DLL injection and in-memory loaders to steal browser credentials, keylog keystrokes and sensitive files, exfiltrating data in 1MB HTTP chunks to C2 servers; it provides IoCs, MITRE ATT&CK mappings, victimology, and mitigation guidance.