Kimsuky has been spotted combining polished AI-generated documents with traditional phishing techniques to spread AsyncRAT, a remote-access trojan This article explores remote access trojan. .

Indicators of Compromise (IoCs): Type Indicator Description C2 IP address 112.216.9[. ]171 AsyncRAT command-and-control address embedded in fox.png, leopard.png, lion.png, and wolf.png IP address 169.254.33[. ]137 Address observed during testing alongside rTom.exe_r and AsyncRAT payloads IP address 170.205.29[.

]83 Published IoC IP address 170.205.30[. ]227 Published IoC IP address 185.27.134[. ]140 Published IoC IP address 27.102.137[. ]126 Published IoC IP address 27.102.137[.

]159 Published IoC IP address 27.102.138[. ]44 Published IoC Domain toks.great-site[. ]net Published IoC Email addresses apollo1030109@gmail[. ]com; awed33@outlook[.

]kr; belendong40@gmail[. ]com; brandonleeodd.93@gmail[. ]com; contrasde@outlook[. ]kr; devlion413@gmail[.

]com Published IoCs Email addresses eros1030109@gmail[. ]com; hera1030109@gmail[. ]com; holowin401@gmail[. ]com; holowin@gmail[.

]com; jecoma@outlook[. ]kr; johnstones19850308@gmail[. ]com Published IoCs Email addresses johnstones8888@outlook[. ]com; kkkkk79@outlook[.

]kr; tomas3015@outlook[. ]kr; trungvo5131993@gmail[. ]com; tttsssuuu@outlook[. ]kr; whitewolf20000312@gmail[.

]com Published IoCs File names apple.png, fox.png, leopard.png, lion.png, rabbit.png; RC4-encrypted .NET AsyncRAT payloads disguised as image files File name rTom.exe_r File stored alongside AsyncRAT payloads File name poqpwoqwdjoweij.ps1; irujkdnjhgttrhdkfdu.ps1; lpieuysjfgtrja.ps1; ms_update.ps1 PowerShell scripts used in the infection chain File names riudxkfngidruhkr.pdf, priujghtjytfcghffgt.txt, bhjfjkfgrtwehjbfgcf.txt Files retrieved through GitHub infrastructure Scheduled task ZHUYHJGTYTFSUHIPOKLKHJHUYGVHGNFH Hidden recurring task used for persistence MD5; 502ebc2356f9f700bbdac444cdefa0da; 61f378c0efc13669dada1fe340c6837b; d2669731cb5ff664dfb5fbfc37637876 Published malware hashes MD5; d2ab3df4762fbde5d86e99a1ad147850; e2e76d5316663a3dc472398b1c01cb9a; 82eb77109cce1e8afca6245c2963e52a; 6302725413076d1aeaee2d7f2b369264 Published malware hashes MD5; 630792a0c0dfad55fb2b19d3e30e9a7d; 430d5f17d5e3f85be18220a7cab0b9ff; f37cec428257cd41153cf43d7f1a1265; 23b9d40f3d620ec87960b4350d42ccc0 Published malware hashes MD5; 33e2110d233d4543830e14c78d53900f; 4422a221851ea6ad15f53cd3aea51c8a; f49bdbe7e6cbb88842afcce3a9fe60e9; b4d87fef16790cbe1df72007d9914966 Published malware hashes MD5; e5af95590a33b9bc64d95808f1fc71b; 785c5672bb14e1d2f07a8318ffec19b; 2136add815cd61d6514f81a23ab8c23 Published malware hashes MD5; 405a73ff669fc282653bd6c42cf87ade; 93377f12fa589f56f6203c692715b395; 8d308406075af0a1e9ec09bafdc0de01; f1388c859a03814443c6f0da341ee594 Published malware hashes MD5; c352a1c07ac866fb6b388e38c6bb1d4; bbe94a343d8bcf02a0554fa271452a51; 2f3cea435292106026e257789036a70e; e1a14a5701848f82c65a55765dc53411 Published malware hashes MD5; 1899faa9d5dd632bb90addca480eaa5; ff4382af3fa7f22f6e97901f20326cc; 12bdb49b406ea5b8628cb7801f47c018; 9b96182b50dad56d891ef230656b37ce Published malware hashes MD5; 62cdadab516ec6c6b37618ad65080a06; 3270ea4ba0238423b5c29667cd760ccd; 7b000aaba8e682a72c6a3e634c070f0; fb057bf5bbf1b0ab9fc27439de4386ed Published malware hashes MD5; 7b8fc151c410055bfa198937825dfd7e; 41000e7ac63d021de798034cbf933e1; c99bcb83fc7723bf166ef08ff3112257; a1244f584ca0b57807f79f26e7f59 Published malware hashes