PULSE NAME
Kimsuky | Ongoing Campaign Using Tailored Reconnaissance Toolkit - SentinelOne
WHITE Kimsuky CyberHunter_NL 2023-05-30 Modified: 2023-05-30
38
IOCs
MEDIUM VOLUME
North Korea-focused information services, human rights activists and defectors in relation to North Korea are the target of an ongoing campaign by a suspected North Korean advanced persistent threat group, according to SentinelLabs.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
VBScript RandomQuery RandomQuery Kimsuky
Indicators of Compromise (6 / 38 total)
All email URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 0288140be88bc3156b692db2516e38f1f2e3f494 2023-05-30
FileHash-SHA1 49c70c292a634e822300c57305698b56c6275b1c 2023-05-30
FileHash-SHA1 84398dcd52348eec37738b27af9682a3a1a08492 2023-05-30
FileHash-SHA1 8f2e6719ce0f29c2c6dbabe5a7bda5906a99481c 2023-05-30
FileHash-SHA1 912f875899dd989fbfd64b515060f271546ef94c 2023-05-30
FileHash-SHA1 96d29a2d554b36d6fb7373ae52765850c17b68df 2023-05-30