PULSE NAME
Analysis of APT-C-55 (Kimsuky) Organization's HappyDoor Backdoor Attack Based on VMP Strong Shell
WHITE APT-C-55 (Kimsuky) AlienVault 2025-07-10 Modified: 2025-08-09
12
IOCs
MEDIUM VOLUME
The APT-C-55 (Kimsuky) group, a North Korean threat actor, has launched a new attack campaign targeting South Korea. They used a disguised Bandizip installation package to deliver malicious code and a VMP-protected HappyDoor trojan for espionage activities. The attack involves remote script loading, multi-stage malware deployment, and information theft. The malware collects sensitive data, including user information, system details, and files from specific directories. It also implements keylogging, screen capture, and mobile device monitoring functionalities. The attack methodology and infrastructure align with Kimsuky's historical patterns, including the use of similar scripts, backdoor families, and domain naming conventions.
Indicators of Compromise (12)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 07fbf46d3a595a6f82e477ed4571294b 2025-07-10
FileHash-MD5 16d30316a6b700c78d021df5758db775 2025-07-10
FileHash-MD5 a6598bbdc947286c84f951289d14425c 2025-07-10
FileHash-MD5 d1ec20144c83bba921243e72c517da5e 2025-07-10
FileHash-MD5 f4cd4449e556b0580c2282fec1ca661f 2025-07-10
FileHash-SHA1 01e61842e05579a4cee0dd67376ad4e09d38fcf7 2025-07-10
FileHash-SHA1 07c7cf4441254e8754aa62150bf8c5365c3825f4 2025-07-10
FileHash-SHA256 5f23b1ca43f6a18e3c9f21d390f5d1e187b1339b07a1dce70f8338f3be320878 2025-07-10
FileHash-SHA256 d75eae7a38df433a4ac5faca0c70a1634729d884e45d14d306b2078fe0a8e5af 2025-07-10
hostname d.appz.p-e.kr 2025-07-10
hostname mrasis.n-e.kr 2025-07-10
hostname u.appw.p-e.kr 2025-07-10