Kimsuky Threat Research Report-2
ID: e56219d4-6088-4b9c-883c-372493ed2346
STIX ID: report--e56219d4-6088-4b9c-883c-372493ed2346
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2025-07-25
Last Modified Date: 2025-07-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report from Aryaka Threat Research Lab documents a multi-stage Kimsuky APT cyber-espionage campaign targeting South Korean entities, detailing an infection chain that begins with malicious LNK/HTA files and uses obfuscated VBScript/PowerShell, persistence, anti-VM checks, reflective DLL injection and in-memory loaders to steal browser credentials, keylog keystrokes and sensitive files, exfiltrating data in 1MB HTTP chunks to C2 servers; it provides IoCs, MITRE ATT&CK mappings, victimology, and mitigation guidance.
