Vexday analysis
Kimsuky é um grupo de espionagem cibernética originário da Coreia do Norte (DPRK), ativo pelo menos desde 2012 e rastreado pelo MITRE ATT&CK sob o identificador G0094 — também referenciado pelos aliases Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43 e TA427. O grupo iniciou suas operações visando agências governamentais sul-coreanas, think tanks e especialistas temáticos, expandindo posteriormente seu escopo para abranger a ONU e organizações nos setores governamental, educacional, de serviços empresariais e manufatureiro nos Estados Unidos, Japão, Rússia e Europa. Suas coletas são focadas em questões de política externa e segurança nacional relacionadas à Península Coreana, política nuclear e sanções internacionais. Ao grupo são atribuídas 3 CVEs conhecidas e 130 técnicas documentadas no framework MITRE ATT&CK.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 130
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 3
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Known infrastructure 39
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
uybwveyvyt62rc.siteAmadeythreatfoxzsv2c62243.spaceAmadeythreatfox82617293c095f7170bea3d3384f8da2bAmadeythreatfox7b0e7c8cc9ca514381a6bfecf879b650Amadeythreatfoxe1c1a8a9d67b3dc8cdce7f357dedf81cfe360ec1Amadeythreatfox3fed685e1b41d37f28a2fbd69ee3755ab4797b5d9b60ca6d904b2c9529af12f8Amadeythreatfoxdc665280d55c2a5393282a7c207a9adfa65d0472Amadeythreatfoxaa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73Amadeythreatfox5ae3941fddd55e92eb7bab8c1b9bc5f4b9fa7d70Amadeythreatfox262373e7649042b5541bcab907599a71Amadeythreatfox5f160eb9a281a5f2a1a6ea1c5743d34fd3c0f1c34407ea1bd2d197e64cfa8c3cAmadeythreatfoxhttp://196.251.107.186/build_x32.exeAmadeyurlhausf8e68cddf13a94d821a4b265172a0e32Amadeythreatfoxe85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52Amadeythreatfox16646bfd7f6554cd170fb373ce813c24f37e829eAmadeythreatfox5d11d7b9b175695c197014bc6aa2fbdbAmadeythreatfoxa86c023a02f1454738b39f753f50777c238b4ea296ffc76cd41c3059f216be10Amadeythreatfoxc25b20a5f15a0f69e0343b539bb4408a4e3739dbAmadeythreatfoxa86c023a02f1454738b39f753f50777c238b4ea296ffc76cd41c3059f216be10Amadeymalwarebazaarhttp://192.162.199.186/aB7xTy2N/mAjOR.phpAmadeythreatfoxe85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52Amadeymalwarebazaarhttp://196.251.107.186/qK3mRv9L/pLdWr.phpAmadeythreatfox267e3d1dc9718ec99fecad28a3f4ec24100d8b0e2c60701289681e39d85fd3dbAmadeymalwarebazaar37.1.213.59:80Amadeythreatfoxhttp://37.1.213.59/y8jdGc5jS/Plugins/cred.dllAmadeyurlhaushttp://37.1.213.59/y8jdGc5jS/Plugins/cred64.dllAmadeyurlhaushttp://37.1.213.59/y8jdGc5jS/index.phpAmadeythreatfoxhttp://196.251.107.104/NuclearBomb.exeAmadeyurlhaushttp://196.251.107.104/sprd2.exeAmadeyurlhaushttp://196.251.107.104/bot_x64.exeAmadeyurlhaus+39 indicators in total. See them all on the IOCs page.
References
Kimsuky uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →