PULSE NAME
Analysis of APT-C-55 (Kimsuky) Organization's HappyDoor Backdoor Attack Based on VMP Strong Shell
WHITE APT-C-55 (Kimsuky) AlienVault 2025-07-10 Modified: 2025-08-09
12
IOCs
MEDIUM VOLUME
The APT-C-55 (Kimsuky) group, a North Korean threat actor, has launched a new attack campaign targeting South Korea. They used a disguised Bandizip installation package to deliver malicious code and a VMP-protected HappyDoor trojan for espionage activities. The attack involves remote script loading, multi-stage malware deployment, and information theft. The malware collects sensitive data, including user information, system details, and files from specific directories. It also implements keylogging, screen capture, and mobile device monitoring functionalities. The attack methodology and infrastructure align with Kimsuky's historical patterns, including the use of similar scripts, backdoor families, and domain naming conventions.
Indicators of Compromise (5 / 12 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 07fbf46d3a595a6f82e477ed4571294b 2025-07-10
FileHash-MD5 16d30316a6b700c78d021df5758db775 2025-07-10
FileHash-MD5 a6598bbdc947286c84f951289d14425c 2025-07-10
FileHash-MD5 d1ec20144c83bba921243e72c517da5e 2025-07-10
FileHash-MD5 f4cd4449e556b0580c2282fec1ca661f 2025-07-10