← Back to Feed

Kim Sooki again? This time, it was disguised as a request for seafood ingredients

September 1, 2026 · AhnLab ASEC · Severity: MEDIUM

A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]

Key Takeaways

  • A threat actor impersonating Kim Sooki disguises malicious files as a request for seafood ingredient information to target victims.
  • Organizations should verify email sender identities and scan attachments before opening files from unknown or unexpected sources.
  • Organizations should review the full article for complete details and implement relevant security measures.
☕ Buy a Coffee