SYMBOLCOMMON_NAMEaka. SYNONYMS
ps1.randomquery (Back to overview)

RandomQuery

Actor(s): Kimsuky


A set of powershell scripts, using services like Google Docs and Dropbox as C2.

References
2024-03-18SecuronixD. Iuzvyk, O. Kolesnikov, T. Peck
Analysis of New DEEP#GOSU Attack Campaign Likely Associated with North Korean Kimsuky Targeting Victims with Stealthy Malware
RandomQuery

There is no Yara-Signature yet.