ATT&CKReferencesSecurelist Kimsuky Sept 2013

Securelist Kimsuky Sept 2013

Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupKimsuky

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1041
Exfiltration Over C2 Channel
GroupKimsuky

Kimsuky has exfiltrated data over its C2 channel.

T1055
Process Injection
GroupKimsuky

Kimsuky has used Win7Elevate to inject malicious code into explorer.exe.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1070.004
File Deletion
GroupKimsuky

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.

T1082
System Information Discovery
GroupKimsuky

Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`.

T1083
File and Directory Discovery
GroupKimsuky

Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways.

T1219.002
Remote Desktop Software
GroupKimsuky

Kimsuky has used a modified TeamViewer client as a command and control channel.

T1543.003
Windows Service
GroupKimsuky

Kimsuky has created new services for persistence.

T1546.001
Change Default File Association
GroupKimsuky

Kimsuky has a HWP document stealer module which changes the default program association in the registry to open HWP documents.

T1547.001
Registry Run Keys / Startup Folder
GroupKimsuky

Kimsuky has placed scripts in the startup folder for persistence and modified the `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce` Registry key.

T1560.003
Archive via Custom Method
GroupKimsuky

Kimsuky has used RC4 encryption before exfil.

T1566.001
Spearphishing Attachment
GroupKimsuky

Kimsuky has used emails containing Word, Excel and/or HWP (Hangul Word Processor) documents in their spearphishing campaigns. Kimsuky has also distributed emails with attached compressed zip files that contained malicious .LNK files masquerading as legitimate files. Kimsuky has delivered tailored PDF documents that contain malicious links.

T1680
Local Storage Discovery
GroupKimsuky

Kimsuky has enumerated drives.

T1685
Disable or Modify Tools
GroupKimsuky

Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user.

T1686
Disable or Modify System Firewall
GroupKimsuky

Kimsuky has been observed disabling the system firewall.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.