Analysis of Kimsuky group using Dropbox for operations
released on 2024-02-05 @ 05:11:53 PM
A recent campaign by the North Korea-linked threat actor Kimsuky distributed malicious LNK files posing as PDFs to download payloads. The payloads used Dropbox APIs and Tutclient RAT to collect info. Kimsuky campaigns increasingly use cloud services and living-off-the-land tactics.