Kimsuky
Active
 
Backdoor
June 2013
 
Windows
2011
 
11-100
TOP TARGETED COUNTRIES:
South Korea
  • Unknown
  • Cyberespionage
  • Data theft
  • Remote control
  • Email accounts on various public mail services are used to control bots and serve as drop zones.
  • We have identified the following mail services that have been abused: mail.bg, hotmail.com, gmail.com, india.com, gmx.com, mail.com, zoho.com, indiatimes.com, 8panther.com
  • Academia/Research
  • Government entities
  • Private companies
  • Strings left by malware author in the compile paths of the malicious samples' bodies suggest the attack has Korean origins. Also we have been able to define the IP addresses from which attackers visited their email accounts to control the bots. All those IP addresses turned out to be Chinese areas bordering North Korea. Internet Providers from these areas are believed to provide Internet into North Korea. All this, as well as the fact that the targets are of specific interest to the North Korean government, could suggest that North Korea might be behind this threat actor.
The blog post and research paper are available at Securelist.com