PULSE NAME
Live C2 Dump Recovering Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger
WHITE Kimsuky dylanroth7 2026-04-13 Modified: 2026-05-13
39
IOCs
MEDIUM VOLUME
On April 11, 2026, researchers analyzed a CHM file (api_reference.chm) tagged as Kimsuky that initiated a three-stage attack chain. The C2 server at check[.]nid-log[.]com had directory listing enabled, allowing recovery of complete source code for all payload stages: a 6,338-byte VBScript performing system reconnaissance and establishing persistence via scheduled task, a 449-byte VBScript bridge to PowerShell, and a 6,234-byte PowerShell keylogger with clipboard monitoring and timed exfiltration. The infrastructure included 79+ domains across 5 C2 IPs spanning Korean VPS providers. The server responded with "Million OK !!!!" signature, matching previously documented Kimsuky infrastructure while showing upgraded Apache/PHP stack. The operation targeted Korean Naver users through credential phishing and tax authority impersonation, with infrastructure linked to previously documented Kimsuky campaigns via shared DAOU Technology subnets.
Indicators of Compromise (6 / 39 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL YARA domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 1eff237dee95172363bfc0342d0389f809f753a6ec5e6848e57b3fd5482e9793 2026-04-13
FileHash-SHA256 7047878f4fbea323148f6554afe616991eb56cc327653972c4213a9017c5e66b 2026-04-13
FileHash-SHA256 85f8f8a3f28d2956776fbbd0365cdb78ac8dc1e6ed12818ef18caed0bb2f74c8 2026-04-13
FileHash-SHA256 a36576a096db24a1c91327eb547dedf52e5bd4b0d4593b88d9593d377585b922 2026-04-13
FileHash-SHA256 af50f35701916d3909f2727cdcbde1a7af47f46eb8db3996905b1c0725aa133f 2026-04-13
FileHash-SHA256 d7c09e7bf79aa9b786dcd9f870427f4a1110f702646fba9d3835215ad3649d0b 2026-04-13