Kimsuky Spear Phishing via Malicious QR Codes
Executive Summary
The Kimsuky APT group, a North Korean state-sponsored entity, is targeting government organizations, think tanks, and academic institutions. The group aims to gather intelligence and steal information through espionage campaigns.
Key TTPs
- Initial Access: Spear phishing emails with malicious attachments or links, sometimes using QR codes.
- Execution: Exploiting legitimate tools like
mshta.exeto download and execute malicious payloads. - Defense Evasion: Using multi-component techniques and disguising LNK files as benign documents.
Campaign Analysis
Kimsuky has bifurcated its tactics, utilizing "Quishing" to deploy the DocSwap Android RAT on mobile devices while using LNK/mshta.exe chains to persist on desktops. This hybrid approach targets both unmanaged personal devices and corporate endpoints.
Targeting & Infrastructure
- Target Profile: Government entities, think tanks, academic institutions, and individuals involved in political, economic, and military affairs, particularly in South Korea, the United States, Japan, and Europe.
- Infrastructure: Use of compromised websites and subdomains mimicking legitimate services.
Relevant Terms
- APT (Advanced Persistent Threat): A sophisticated, long-term cyberattack campaign conducted by a skilled actor.
- Spear Phishing: A targeted phishing attack that focuses on specific individuals or organizations, often using personalized information to increase success.
Source: SecurityWeek
