← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Live C2 Dump Recovering Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger
On April 11, 2026, researchers analyzed a CHM file (api_reference.chm) tagged as Kimsuky that initiated a three-stage attack chain. The C2 server at check[.]nid-log[.]com had directory listing enabled, allowing recovery of complete source code for all payload stages: a 6,338-byte VBScript performing system reconnaissance and establishing persistence via scheduled task, a 449-byte VBScript bridge to PowerShell, and a 6,234-byte PowerShell keylogger with clipboard monitoring and timed exfiltration. The infrastructure included 79+ domains across 5 C2 IPs spanning Korean VPS providers. The server responded with "Million OK !!!!" signature, matching previously documented Kimsuky infrastructure while showing upgraded Apache/PHP stack. The operation targeted Korean Naver users through credential phishing and tax authority impersonation, with infrastructure linked to previously documented Kimsuky campaigns via shared DAOU Technology subnets.
MITRE ATT&CK & Malware Families
Indicators of Compromise (6 / 39 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 1eff237dee95172363bfc0342d0389f809f753a6ec5e6848e57b3fd5482e9793 | — | 2026-04-13 | |
| FileHash-SHA256 | 7047878f4fbea323148f6554afe616991eb56cc327653972c4213a9017c5e66b | — | 2026-04-13 | |
| FileHash-SHA256 | 85f8f8a3f28d2956776fbbd0365cdb78ac8dc1e6ed12818ef18caed0bb2f74c8 | — | 2026-04-13 | |
| FileHash-SHA256 | a36576a096db24a1c91327eb547dedf52e5bd4b0d4593b88d9593d377585b922 | — | 2026-04-13 | |
| FileHash-SHA256 | af50f35701916d3909f2727cdcbde1a7af47f46eb8db3996905b1c0725aa133f | — | 2026-04-13 | |
| FileHash-SHA256 | d7c09e7bf79aa9b786dcd9f870427f4a1110f702646fba9d3835215ad3649d0b | — | 2026-04-13 |