Kimsuky's Phishing and Payload Tactics

I co-authored this Rapid7 white paper with Natalie Zargarov and Anna Širokova in 2024. It examines Kimsuky’s social engineering and payload tactics. This overview revisits that research; the findings reflect the reporting period.

Read the full white paper (PDF, 18 pages).

Originally published 16 July 2024 · Archived PDF

Building trust before delivery #

The report describes repeated correspondence before credential phishing or payload delivery, using credible personas and tailored lures.

Email exchanges followed by a cloud-hosted archive, LNK file, PowerShell and final payloads.
Rapid7, figure 1, page 4: phishing and delivery chain.

Disguised files and execution #

One example used a password-protected archive containing a shortcut disguised as a Hangul document. The research also examines LNK toolmarks, CHM files and scripting-based execution.

Archive contents showing an HWP document name with an additional LNK extension.
Rapid7, figure 4, page 7: disguised shortcut.

An MSC sample presented a document lure through Microsoft Management Console.

Microsoft Management Console displaying a Word-style icon and document lure.
Rapid7, figure 9, page 10: MSC document lure.

Attribution needs context #

Shared LNK-builder characteristics alone were insufficient for attribution. The report combines toolmarks with targeting, payloads and infrastructure, and includes further analysis, references and indicator links.

Figures extracted from the original Rapid7 white paper. Copyright Rapid7, 2024.