logo

rapid7-Kimsukys-Phishing-and-Payload-Tactics_wp.pdf

ID: f3313967-ab39-4067-a88f-267e80e7a996

STIX ID: report--f3313967-ab39-4067-a88f-267e80e7a996

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2024-07-16

Last Modified Date: 2024-07-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Rapid7 white paper analyzes Kimsuky — a DPRK-linked APT — describing its social‑engineering focused phishing campaigns, delivery chains (email/OneDrive/Google Drive -> RAR -> LNK/CHM -> PowerShell), payloads (embedded/reflective PowerShell loaders, XeroRAT, AppleSeed/AlphaSeed, BabyShark), persistence techniques, and infrastructure patterns; it includes sample artifacts, code snippets, IOCs, and detection recommendations for defenders.