Warning Against Distribution of Malware Disguised as Research Papers

June 23, 2025, 7:57 p.m.

Description

The Kimsuky group has launched a sophisticated phishing attack disguised as a request for paper review from a professor. The attack involves a password-protected HWP document with a malicious OLE object, which creates six files upon opening. When executed, these files perform various malicious activities, including collecting system information, downloading additional files, and establishing remote access through AnyDesk. The threat actors use legitimate software and cloud storage services like Dropbox as part of their attack infrastructure. The malware hides its presence by concealing AnyDesk's interface, making detection difficult for users. This case highlights the evolving tactics of APT groups and the importance of cautious handling of files from unknown sources.

Date

  • Created: June 18, 2025, 5:46 p.m.
  • Published: June 18, 2025, 5:46 p.m.
  • Modified: June 23, 2025, 7:57 p.m.

Indicators

  • 103.130.212.116
  • 103.149.98.230
  • niva.serverpit.com