Madi is malware associated in the provided content with a months-long cyber-espionage campaign targeting South Korean think tanks and related organizations, including The Sejong Institute, the Korea Institute for Defense Analyses (KIDA), South Korea’s Ministry of Unification, Hyundai Merchant Marine, and possibly unihope.kr; the report states 11 targeted organizations were in South Korea and two in China. The intrusion chain uses an initial DLL loader that decrypts and loads an encrypted second-stage library from resources, writes a decrypted spying DLL to the temp directory, then installs itself in %windir%\System32 as KBDLV2.DLL or AUTO.DLL and establishes persistence via Windows services such as DriverManage, WebService, and WebClientManager. On Windows 7 it uses Metasploit Win7Elevate code to inject into explorer.exe. The malware collects system information, logs keystrokes and active window names, performs directory listings, steals HWP documents by hijacking .HWP file associations, and supports remote control through modified TeamViewer 5.0.9104 components installed as netsvcs.exe with a Remote Access Service. It disables Windows Firewall, attempts to disable AhnLab firewall settings, and disables the Windows Security Center service. Command-and-control is conducted through the Bulgarian webmail service mail.bg using Wininet API automation; hardcoded bot accounts include beautifl@mail.bg, ennemyman@mail.bg, fasionman@mail.bg, happylove@mail.bg, lovest000@mail.bg, monneyman@mail.bg, sportsman@mail.bg, and veryhappy@mail.bg, while reports are sent to iop110112@hotmail.com and rsh1213@hotmail.com. Bots poll roughly every 30 minutes and receive tasking via email subject tags including Down_0, Down_1, Happy_0, Happy_2, and ddd_3. Exfiltrated data is packaged into files named like <system time>_<mail.bg account>.txt, encrypted with RC4 using an MD5-derived key, with key material additionally protected using RSA, then emailed and deleted from disk. Additional payloads can be delivered encrypted with an RC4 key derived from the string rsh!@!#. The content discusses likely attribution to Kimsuky based on Korean-language artifacts, Hotmail registration names containing Kim, and observed operator IPs geolocated to China’s Jilin and Liaoning provinces, while noting this is circumstantial and not conclusive. Reported file and path indicators include C:\Program Files\Common Files\System\Ole DB\oledvbs.inc, C:\Program Files\Common Files\System\Ole DB\msolui80.inc, C:\WINDOWS\setup.log, C:\WINDOWS\msdatt.bat, C:\WINDOWS\msdatl3.inc, msdaipp.cnt, sqlsoldb.exe, C:\Windows\taskmgr.exe, C:\Windows\System32\netsvcs.exe, and registry paths HKLM\Software\Goldstager\Version5 and HKLM\Software\Coinstager\Version5. One sample of a directory-listing module was noted as infected with the Viking virus. The content also notes a reference stating, "We saw this same format in the Madi malware," but does not provide broader high-confidence details beyond the espionage toolset described here.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool referenced in the content without additional description.
Referenced for similarity in keystroke log formatting (window title + keystrokes). The content does not indicate Madi is deployed in this campaign—only used as a comparison point.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.