A Kimsuky-associated phishing campaign targets Korean users with a malicious LNK file disguised as a seafood ingredient purchase request. Execution triggers a multi-stage attack involving a decoy HWP document, an obfuscated JavaScript payload, and a PowerShell script that exfiltrates system data to Backblaze B2 cloud storage and downloads further commands.
HWP document
1 post
Kim Sooki again? This time, it was disguised as a request for seafood ingredients