No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

North Korean APT Uses Malicious Microsoft OneDrive Links to Spread New Malware

May 9, 2023
in Protection
0
North Korean APT Uses Malicious Microsoft OneDrive Links to Spread New Malware



North Korean cyber espionage group Kimsuky has expanded its attack arsenal with a new spear-phishing campaign that uses Microsoft OneDrive links in documents armed with malicious macros that drop novel reconnaissance malware.

Researchers at SentinelLabs observed a new campaign from the threat actor targeting staff of Korea Risk Group (KRG), an information and analysis firm specializing in matters directly and indirectly impacting the Democratic People’s Republic of Korea (DPRK).

They believe the same campaign is also being used to target individuals at universities — a new victim pool for Kimsuky — as well typical targets such as government organizations, research centers, and think tanks in North America, Europe, and Asia, they revealed in a recent blog post.

The campaign shows the longstanding APT wielding new malware dubbed ReconShark that’s a component of — and thus named for — a custom malware variant called BabyShark previously used in campaigns toward the end of last year, SentinelOne’s Tom Hegel and Aleksandar Milenkoski wrote in the post.

ReconShark can exfiltrate information, including deployed detection mechanisms and hardware information — to gain access to targeted networks, basing their assessment on overlaps in file-naming conventions, used malware staging techniques, and code format, the researchers said.

The malware appears to be “part of a Kimsuky-orchestrated reconnaissance operation that enables subsequent precision attacks, possibly involving malware specifically tailored to evade defenses and exploit platform weaknesses,” the researchers wrote in the post.

Carefully Crafted Emails

While spear-phishing is often part of Kimsuky’s modus operandi, the group is paying special attention to craft emails in the latest campaign carefully, so they don’t raise suspicion, the researchers said.

“[They] are made with a level of design quality tuned for specific individuals, increasing the likelihood of opening by the target,” the researchers wrote. “This includes proper formatting, grammar, and visual clues, appearing legitimate to unsuspecting users.”

Notably, the targeted emails, which contain links to download malicious documents, and the malicious documents themselves, abuse the names of real individuals whose expertise is relevant to the lure subject, such as political scientists, the researchers said.

The campaign against KRG specifically used Microsoft OneDrive to host the malicious document — which contains macros that execute ReconShark — presented for download in the message.

For example, a lure email used in the campaign included a OneDrive shared file link to a password protected document file named “Research Proposal-Haowen Song.doc” that contained a malicious macro for downloading the malware, they said.

Once downloaded, the main responsibility of ReconShark is to exfiltrate information about the infected platform, such as running processes, information about the battery connected to the system, and deployed endpoint threat detection mechanisms, the researchers said. The malware is similar to previous BabyShark variants in its reliance on Windows Management Instrumentation (WMI) to query process and battery information, they added.

However, ReconShark can do more than just steal data about the targeted system, the researchers said. It also can deploy further payloads in a multi-stage manner that are implemented as scripts (VBS, HTA, and Windows Batch), macro-enabled Microsoft Office templates, or Windows DLL files, they said.

“ReconShark decides what payloads to deploy depending on what detection mechanism processes run on infected machines,” the researchers wrote in the post.

Expanding its Target Base

Kimsuky, also tracked as Thallium, has been on various researchers’ radar screens since 2018, and its previous activity — which SentinelOne said dates back to 2012 — has been widely reported. In earlier attacks, the group mainly focused on conducting cyber espionage against research institutions, geo-political think tanks, and — particularly during the height of the pandemic — pharmaceutical companies.

Though Kimsuky’s recent activities have raised its profile among security researchers, the group appears undaunted and continues to expand its operations. In fact, the new campaign shows Kimsuky adding universities to its range of targets, which Dror Liwer, co-founder of cybersecurity company Coro, says is “worrying” due to their general lack of cybersecurity defenses and awareness programs.

“We have seen a triple-digit increase in attacks on educational institutions in the US in the last year, which is driven by a perfect storm from an attacker’s perspective: Extremely valuable data, and lacking defenses,” he tells Dark Reading in an email.

Overall, organizations can thwart attacks from Kimsuky and other actors’ spear-phishing campaigns in general by practicing overall good email security hygiene, such as employing scanning tools to check incoming messages for suspicious activity, so they are flagged before they even reach users.

Educating employees and anyone else using an organization’s email system can also help them spot malicious messages that slip through other security defenses and thus avoid compromise, experts said.

Editorial Team

Editorial Team

Related Posts

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms'
Protection

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘A Knight of the Seven Kingdoms’

April 22, 2026
How to Spot AI Audiobooks on Libby
Protection

How to Spot AI Audiobooks on Libby

April 21, 2026
The Best Last-Minute Deals From Home Depot's 'Spring Black Friday' Sale
Protection

The Best Last-Minute Deals From Home Depot’s ‘Spring Black Friday’ Sale

April 21, 2026
10 Hacks Every Apple CarPlay User Should Know
Protection

10 Hacks Every Apple CarPlay User Should Know

April 21, 2026
The Samsung Galaxy Watch Ultra Is Over $100 Off Right Now
Protection

The Samsung Galaxy Watch Ultra Is Over $100 Off Right Now

April 21, 2026
11 of the Biggest Moments in Tim Cook's Time As Apple CEO
Protection

11 of the Biggest Moments in Tim Cook’s Time As Apple CEO

April 21, 2026
Load More
Next Post
Imran Khan arrested by Pakistan anti-corruption force

Imran Khan arrested by Pakistan anti-corruption force

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Chainalysis: Crypto Money Laundering Surged to $82 Billion in 2025

    0 shares
    Share 0 Tweet 0
  • Explainer-How the State of the Union became a stage for political confrontation

    0 shares
    Share 0 Tweet 0
  • Strait of Hormuz tensions keep WTI crude oil market on edge as April deadline nears

    0 shares
    Share 0 Tweet 0
  • What It Could Mean For XRP

    0 shares
    Share 0 Tweet 0

Latest News

DoorDash Stablecoin Payments Move Could Expand Mainstream Crypto Checkout

DoorDash Stablecoin Payments Move Could Expand Mainstream Crypto Checkout

April 22, 2026
0

DoorDash announced on April 21, 2026, that it is integrating stablecoin crypto payment infrastructure through Tempo – a layer-1 blockchain...

Stocks making the biggest moves after hours: ADBE, UAL, COF

Stocks making the biggest moves after hours: ADBE, UAL, COF

April 22, 2026
0

Check out the companies making headlines after the bell : United Airlines — Shares rose about 1% even after the...

Senior Associate Director, Executive MBA Career Advisor & Programming Lead

Senior Associate Director, Executive MBA Career Advisor & Programming Lead

April 22, 2026
0

Senior Associate Director, Executive MBA Career Advisor & Programming LeadUniversity OverviewThe University of Pennsylvania, the largest private employer in Philadelphia,...

Wendel and BNPP AM Alts Prime take stakes in Committed Advisors

Wendel and BNPP AM Alts Prime unit acquire stakes in Committed Advisors

April 22, 2026
0

Listed investment firm Wendel has completed its acquisition of a controlling stake in Committed Advisors, with BNP Paribas Asset Management...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.