← Back to Feed
Kim Sooki again? This time, it was disguised as a request for seafood ingredients
September 1, 2026 · AhnLab ASEC · Severity: MEDIUM
A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. It then extracts system information to an external location, downloads and executes additional commands, […]
Key Takeaways
- A threat actor impersonating Kim Sooki disguises malicious files as a request for seafood ingredient information to target victims.
- Organizations should verify email sender identities and scan attachments before opening files from unknown or unexpected sources.
- Organizations should review the full article for complete details and implement relevant security measures.