PULSE NAME
Live C2 Dump Recovering Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger
WHITE Kimsuky dylanroth7 2026-04-13 Modified: 2026-05-13
39
IOCs
MEDIUM VOLUME
On April 11, 2026, researchers analyzed a CHM file (api_reference.chm) tagged as Kimsuky that initiated a three-stage attack chain. The C2 server at check[.]nid-log[.]com had directory listing enabled, allowing recovery of complete source code for all payload stages: a 6,338-byte VBScript performing system reconnaissance and establishing persistence via scheduled task, a 449-byte VBScript bridge to PowerShell, and a 6,234-byte PowerShell keylogger with clipboard monitoring and timed exfiltration. The infrastructure included 79+ domains across 5 C2 IPs spanning Korean VPS providers. The server responded with "Million OK !!!!" signature, matching previously documented Kimsuky infrastructure while showing upgraded Apache/PHP stack. The operation targeted Korean Naver users through credential phishing and tax authority impersonation, with infrastructure linked to previously documented Kimsuky campaigns via shared DAOU Technology subnets.
Indicators of Compromise (5 / 39 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL YARA domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 51ab17a51cc000bbae89980082c57281c4c0b462 2026-04-13
FileHash-SHA1 66af61e3e376284f691d449d0042e8b2c1174278 2026-04-13
FileHash-SHA1 6aa51c23f0319a6b940072274adf47a0c29f27b6 2026-04-13
FileHash-SHA1 a76af8176da28fdab47f9a77d50eb0e89f2b8557 2026-04-13
FileHash-SHA1 f759ccb6886234c63a66abd6102c636a46d1eba8 2026-04-13