Listen to this Post
In a recent development, cybersecurity researchers have identified a dangerous campaign tied to the North Korean state-sponsored threat actor, Kimsuky, exploiting vulnerabilities to infiltrate systems. Known as Larva-24005, this attack leverages the now-patched BlueKeep vulnerability in Microsoft Remote Desktop Services (RDP) as a primary access point. Discovered by AhnLab Security Intelligence Center (ASEC), the attack utilizes multiple sophisticated techniques to bypass defenses and install malicious software.
The Kimsuky group, known for its advanced and persistent attacks, has been observed targeting critical industries across several countries, primarily focusing on software, energy, and financial sectors in South Korea and Japan. This campaign started in October 2023 and continues to evolve, posing a significant threat to global cybersecurity.
The Exploitation of BlueKeep (CVE-2019-0708)
One of the most alarming aspects of this attack is its use of the BlueKeep vulnerability (CVE-2019-0708), a flaw in Microsoft’s Remote Desktop Services that allows remote code execution. This critical vulnerability, with a CVSS score of 9.8, could enable attackers to remotely install arbitrary programs, steal sensitive data, or even create new user accounts with full rights on the target system.
Although Microsoft patched BlueKeep back in May 2019, many systems remain vulnerable due to insufficient updates or configuration errors. Kimsuky exploited this flaw to gain initial access to targeted networks. While a scanner for the vulnerability was discovered within the compromised system, there’s no concrete evidence that it was actively used in this attack.
Phishing and Equation Editor Vulnerability
In addition to exploiting BlueKeep, Kimsuky used phishing emails with malicious attachments to trigger the Equation Editor vulnerability (CVE-2017-11882). This flaw, rated 7.8 on the CVSS scale, enables attackers to execute arbitrary code when a victim opens a specially crafted file. By embedding such files in phishing emails, the attackers were able to infect victim machines and maintain persistence.
Malware Deployment and Persistence
Once Kimsuky gained access to a target system, the attackers deployed several malicious tools. A dropper, which is a type of malware designed to install other malicious software, was used to deliver MySpy—an information-stealing Trojan. Additionally, an RDPWrap tool was deployed, allowing the attackers to maintain Remote Desktop Protocol (RDP) access, even after the system was patched or rebooted.
The attackers then employed keyloggers, such as KimaLogger and RandomQuery, to capture sensitive information, including usernames, passwords, and other critical data. This allowed Kimsuky to monitor and record user activity, further exfiltrating valuable intelligence.
Targeted Sectors and Global Reach
The campaign has primarily targeted organizations in South Korea and Japan, with a particular focus on the software, energy, and financial sectors. However, the reach of the attack is far broader, impacting countries like the United States, China, Germany, Singapore, South Africa, the Netherlands, Mexico, Vietnam, Belgium, the United Kingdom, Canada, Thailand, and Poland. This wide geographical spread highlights the growing threat posed by Kimsuky and similar state-backed threat actors.
Since October 2023, the campaign has evolved, with new tactics being employed to bypass traditional defenses. While the initial access vectors—BlueKeep and phishing—are well-known, the attackers’ ability to maintain persistent access and deploy sophisticated malware makes this threat particularly concerning.
What Undercode Say:
The Kimsuky campaign serves as a chilling reminder of the persistent threat posed by state-sponsored cyber actors. The group’s ability to exploit a combination of well-known vulnerabilities, such as BlueKeep and Equation Editor, demonstrates their ongoing commitment to using tried-and-true methods of attack to infiltrate high-value targets.
Despite the fact that Microsoft patched the BlueKeep vulnerability years ago, the attackers’ ability to target systems that have not been properly updated or configured underscores the critical need for organizations to regularly patch their systems and ensure that all security measures are in place. The fact that a vulnerability scanner for BlueKeep was discovered on a compromised system is also concerning, as it suggests that these attackers may be systematically scanning networks for vulnerable systems.
Kimsuky’s use of phishing emails with malicious attachments is another common tactic seen in many other cyberattacks, emphasizing the need for robust email filtering and user education. Even though phishing techniques are widely known, their continued success highlights the importance of vigilance in cybersecurity practices.
The deployment of keyloggers like KimaLogger and RandomQuery is particularly alarming, as it suggests that the attackers are not only interested in exfiltrating data but also in monitoring user behavior in real time. By capturing keystrokes, they can gather sensitive information such as login credentials, private communications, and internal documents, making it easier for them to conduct further attacks.
Another significant takeaway from this campaign is the strategic focus on high-value industries such as software, energy, and finance. These sectors are often prime targets due to the sensitive data they hold and the critical infrastructure they support. By targeting these industries, Kimsuky is likely seeking both intelligence and leverage for future political or economic actions.
As the campaign continues to evolve, it is essential for organizations to remain proactive in their defense strategies. This includes not only applying patches but also employing advanced threat detection systems, conducting regular security audits, and training employees to recognize phishing attempts.
Fact Checker Results
- Kimsuky’s exploitation of BlueKeep (CVE-2019-0708) is confirmed, although many systems remain unpatched.
- The Equation Editor vulnerability (CVE-2017-11882) was correctly identified as a second access vector.
- No evidence has surfaced that BlueKeep was actively exploited on systems, though its presence was detected in scans.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.quora.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2





