Analysis of the threat case of kimsuky group using 'ClickFix' tactic

July 2, 2025, 7:49 a.m.

Description

The Kimsuky group has adopted a deceptive tactic called 'ClickFix' to trick users into unknowingly participating in attack chains. This method involves disguising malicious instructions as troubleshooting guides or security document verification procedures. The campaign is believed to be an extension of Kimsuky's ongoing 'BabyShark' threat activity. The tactic has evolved from VBS-based attacks to more sophisticated email-based and website-delivered methods. Attackers impersonate legitimate entities and use multilingual manuals to guide victims through seemingly harmless steps that actually execute malicious code. The group's infrastructure and linguistic patterns point to North Korean origin. To counter such threats, EDR-based defense strategies are crucial for detecting obfuscated malware and identifying abnormal behaviors.

Date

  • Created: July 2, 2025, 7:14 a.m.
  • Published: July 2, 2025, 7:14 a.m.
  • Modified: July 2, 2025, 7:49 a.m.

Indicators

  • 38.180.157.197
  • 65.254.248.151
  • 162.0.229.227
  • 211.170.73.245
  • 210.179.30.213
  • 121.179.161.231
  • 118.194.228.184
  • 115.92.4.123
  • 106.243.157.158
  • 112.74.194.45
  • 172.86.111.75
  • 1.223.129.234
  • 118.193.69.151
  • 103.149.98.248
  • 103.149.98.247
  • www.online.check-computer.kro.kr
  • securedrivelog.register.im
  • securedrive.servehttp.com
  • securedrive.privatedns.org
  • securedrive.fin-tech.com
  • secure.drive.polices.site
  • online.lecture-site.kro.kr
  • securedrive-overseas-state.bit-albania.com
  • nid.naver.rkfd.com
  • mspro.kro.kr
  • msprovider.menews.o-r.kr
  • login.androclesproject.o-r.kr
  • kida.plusdocs.kro.kr
  • e-securedrive.assembly.twoon.co.kr
  • androcl.csproject.org
  • accounts-porfile.serveirc.com
  • account-profile.servepics.com
  • tenelbox.store
  • naunsae.store
  • temuco.xyz
  • raedom.store
  • konamo.xyz
  • cukumam.shop
  • cafe24.pro
  • bikaro.store

Attack Patterns

Additional Informations

  • Defense
  • Government
  • Australia
  • Taiwan
  • China
  • Japan
  • United States of America