Security1 distinct publisher3 min readPublished
AhnLab's latest writeup on the North Korean group shows the bespoke code doing account hiding and port forwarding while a shipped Windows feature carries the actual session.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
RDP Wrapper exists to make Terminal Services answer on a Windows build that was not sold with it, so the detectable event is not a file but a host whose remote-desktop service is running when its own baseline says it should not be [5]. The account work has the same shape: a local account that appears on the box but not in inventory, and a session count above one on a machine that has a single user [6]. RevClient adds a network-side delta to that list, since its jobs are creating users and switching on port forwarding when told to over C&C [9].
Notice how narrowly the custom code is scoped. Of the five remote-control mechanisms AhnLab names in this group's history, four are software an organisation either ships already or can download without a warning [17]. What stays bespoke is the small stuff that bends the sanctioned channel rather than replacing it: concealing the added account, allowing concurrent sessions, opening the forward [6][9]. The Chrome Remote Desktop cases push this further, because a session carried by the browser's own service does not present as an unusual listener at all [7]; the evidence lives on the host, in who was logged on and how many of them there were.
The execution path repeats the pattern. pow.ps1 decrypts a data file under %APPDATA%\Microsoft, runs it in memory, and the resulting injector places the final payload inside MSBuild.exe, a legitimate Microsoft program [13]. The first-stage batch file, for its part, enumerates installed antivirus products using WMIC before pulling down script-type malware [11]. The keylogger is a PowerShell file writing to %APPDATA%\k.log, launched by a VBScript named after OneNote [12].
Two things in the writeup say plainly that indicator lists will not hold. BabyShark's C&C address changed part way through, which AhnLab reads as the operator updating the implant after installation [15], and the intrusion continued with malware and server addresses being swapped as it went [16]. Meanwhile the PDB data on the RDP tooling suggests recent compilation of features already seen in earlier cases [8]. The behaviour is old, the binaries are new, and the addresses are disposable.
What does not rotate is the target set and the working method: spear phishing into defence, diplomatic and academic bodies, with the goal of taking internal information and technology out [3]. A group that has been at this since 2013 [1] has had a long time to learn which detections those targets actually run. The durable signals are unglamorous ones, and they are all about the state of sanctioned software: remote-desktop services enabled against policy, local account deltas, more sessions than users, and forwarded ports on machines that have no business forwarding anything.
Ranked by verification strength, evidence, and original report placement.
The most commonly used method for remote control by the group is Remote Desktop Protocol; in environments without RDP, the open-source tool RDP Wrapper is installed.
Once RDP is installed, a user account is added for RDP access, or additional malware is used to conceal the added account and configure multiple RDP sessions.
In the latest cases the group installed BabyShark through presumed spear phishing before installing various RDP-related malware strains; the tools have features similar to past cases, but their PDB information suggests they were created recently for use in attacks.
The loader pow.ps1 decrypts the file %APPDATA%\Microsoft\desktop.r7u and executes it in memory; the decrypted file is an injector that, if desktop.r3u exists in the same path, decrypts it and injects it into MSBuild.exe, a legitimate program.
Kimsuky is a threat group known to be supported by North Korea and has been active since 2013.
The group usually launches spear phishing attacks on the national defense, diplomatic and academic sectors, defense and media industries, and national organizations, with the goal of exfiltrating internal information and technology from targets.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed first-party forensics, single vendor, key artifact missing
The report supplies concrete, checkable artifacts: file names and paths (hwp.bat, k.ps1, %APPDATA%\k.log, OneNote.vbs, pow.ps1, desktop.r7u, desktop.r3u, CustomVerification.DIC, multiple.exe, process.exe), quoted PDB build paths, injection targets, and the exact termsrv.dll rename-and-replace sequence. It is weakened by being one vendor's telemetry with no independent corroboration in the cluster, an initial vector that is explicitly presumed rather than proven, and a final injected payload that was never obtained.
Confirmed in-the-wild use, undisclosed scale
The tradecraft is observed rather than hypothetical: an actual compromised system with a full toolchain, plus cited prior cases using RDP Wrapper, TinyNuke, TightVNC and Chrome Remote Desktop. Scale is unmeasurable from the material -- no victim count, no sector or country for this case, no timeline of dwell time or containment -- so this reflects demonstrated but narrowly documented usage.
Restrained reporting, slightly ahead of what was recovered
The writeup is technical and largely avoids overstatement, but a few conclusions run modestly ahead of the artifacts: recency of the tooling is inferred from PDB build paths, the final RAT is named only by analogy to past cases and a third-party report for a file that was never obtained, and continuous updating of BabyShark is inferred from a C&C address change. The cluster's headline framing about detection shifting to configuration is a fair reading of the enumerated tooling but is not stated by the publisher.
Commercial AV vendor publishing on its own research blog
The sole source is AhnLab's ASEC blog. AhnLab sells endpoint security, so threat-intelligence publication supports product credibility and demand, and prior ASEC posts are cross-linked. Countervailing signals: the analysis is artifact-level rather than product-pitch, limitations are stated plainly (file not procured, delivery presumed), and a third-party researcher (Huntress) is credited. No pricing, product SKU or promotional claim appears in the visible text.
Credible and specific, but uncorroborated and unscoped
Confidence is held up by the granularity and internal consistency of the forensic detail and by the publisher's willingness to flag what it could not recover. It is held down by single-source coverage with no independent confirmation, absence of any victimology or scale, a presumed initial access vector, and an unidentified final payload.
security
Kimsuky adds Chrome Remote Desktop to a toolkit it never retires1 distinct publisher
security
PavinLoader: the lures keep changing, the MSBuild stage does not1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
security
Gunra Goes Franchise: Conti's Leaked Code Now Ships With a Builder and an Affiliate Panel2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026