15-09-2026
Analysis of the APT-C-55 (Kimsuky) group’s attack chain for using disguised installation packages to deploy remote-access trojans
https://mp.weixin.qq.com/s/9ilhH-WUqeNCStDfbrBsrw
Report completeness: Medium
Actors/Campaigns:
Kimsuky
Threats:
Process_hacker_tool
ChatGPT TTPs:
do not use without manual checkT1010, T1027, T1027.009, T1027.013, T1033, T1036, T1036.008, T1041, T1053.005, T1057, have more...
IOCs:
Hash: 4
File: 6
Url: 4
IP: 1
Domain: 0
Email: 0
BrowserExtension: 0
Soft:
Google Chrome, Chrome, InfinityFree
Algorithms:
xor, base64, aes, md5
Win API:
Program
Languages:
powershell, javascript, cscript