rapid7-Kimsukys-Phishing-and-Payload-Tactics_wp.pdf
ID: f3313967-ab39-4067-a88f-267e80e7a996
STIX ID: report--f3313967-ab39-4067-a88f-267e80e7a996
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2024-07-16
Last Modified Date: 2024-07-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Rapid7 white paper analyzes Kimsuky — a DPRK-linked APT — describing its social‑engineering focused phishing campaigns, delivery chains (email/OneDrive/Google Drive -> RAR -> LNK/CHM -> PowerShell), payloads (embedded/reflective PowerShell loaders, XeroRAT, AppleSeed/AlphaSeed, BabyShark), persistence techniques, and infrastructure patterns; it includes sample artifacts, code snippets, IOCs, and detection recommendations for defenders.
