Malware Disguised as Installer from Korean Public Institution (Kimsuky Group)

Malware Disguised as Installer from Korean Public Institution (Kimsuky Group)

AhnLab SEcurity intelligence Center (ASEC) recently discovered the Kimsuky group distributing malware disguised as an installer from a Korean public institution. The malware in question is a dropper that creates the Endoor backdoor, which was also used in the attack covered in the previous post, “TrollAgent That Infects Systems Upon