RandomQuery is a malware family associated with the North Korean threat actor Kimsuky. Reported uses include reconnaissance, information theft, and keylogging. In one SentinelLABS-described campaign, Kimsuky delivered a VBScript-only variant of RandomQuery via Korean-language phishing emails sent from Daum accounts to North Korea-focused information services, human rights activists, and DPRK-defector support organizations. The lure was a password-protected archive containing a CHM file; a malicious Shortcut object in the CHM created a Base64-encoded file in %USERPROFILE%\Links, used certutil to decode it into a VBScript payload such as mini.vbs, and established persistence through HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. The first stage contacted attacker infrastructure over HTTP GET, and the second-stage payload was assessed as a VBScript variant of RandomQuery.
This RandomQuery variant modified Internet Explorer-related registry settings under HKCU\Software\Microsoft\Internet Explorer\Main, including Check_Associations=no and DisableFirstRunCustomize=1, and set HKCU\Software\Microsoft\Edge\IEToEdge\RedirectionMode=0 to prevent IE-to-Edge redirection. Earlier variants reportedly used the InternetExplorer.Application object for C2 communications, while the analyzed variant used Microsoft.XMLHTTP. It collected basic system information via WMI classes Win32_ComputerSystem, Win32_OperatingSystem, and Win32_Processor, including computer name, processor speed, OS version, and physical memory. It also enumerated files and subdirectories in Desktop, Documents, Favorites, Recent, Program Files, Program Files (x86), and Downloads, and gathered running process and session ID information via Win32_Process. Collected data was Base64-encoded and exfiltrated via HTTP POST to attacker-controlled URLs; reported examples included file.com-port.space/indeed/show.php with differing query parameters for staging and exfiltration. The analyzed samples used the HTTP POST boundary string c2xkanZvaXU4OTA, which researchers used to pivot to additional historical RandomQuery variants.
RandomQuery is also described in other Kimsuky reporting as part of the group’s broader malware arsenal alongside PebbleDash, BabyShark, AppleSeed, xRAT, XenoRAT, and TutRAT. Separate reporting stated that in the final stage of a 2025 Kimsuky intrusion campaign, attackers deployed KimaLogger or RandomQuery keyloggers to record keystrokes after exploiting vulnerabilities including BlueKeep (CVE-2019-0708) and Microsoft Office Equation Editor (CVE-2017-11882), and after installing MySpy and RDPWrap. Additional reporting in Chinese described RandomQuery-related activity and an associated information-stealing component that stole sensitive data including system details and browser-related data. Reported infrastructure patterns tied to the VBScript campaign included uncommon TLDs such as .space, .asia, .click, and .online, with domains crafted to resemble legitimate .com naming patterns, including com-def.asia, com-www.click, and com-otp.click.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The campaign focuses on file reconnaissance and information exfiltration using a variant of the RandomQuery malware, enabling subsequent precision attacks.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
RandomQuery also enumerates the process and session IDs of running processes using the Win32_Process WMI class.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Keylogger malware used to record keystrokes on compromised systems.
A Kimsuky-used VBScript malware family employed for reconnaissance and exfiltration. In this campaign, it gathers system and hardware details, enumerates files and folders in key user and program directories, lists running processes, establishes persistence via the Run registry key, communicates with C2 over HTTP, and exfiltrates collected data in Base64-encoded POST requests.
Information-stealing component/campaign associated with Kimsuky, stealing system details and browser-related data via multi-stage payload deployment.
Named as part of Kimsuky's proprietary malware arsenal, but no further technical details are provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.