ReconShark is a reconnaissance malware component used by the North Korean threat actor Kimsuky, also tracked as TA427/APT43/THALLIUM/Emerald Sleet and associated with broader North Korean espionage activity. Reporting assesses it as an evolved reconnaissance component of the BabyShark malware family. It has been used in targeted spear-phishing and social-engineering campaigns against individuals and organizations focused on North Korean affairs, including experts in DPRK issues, staff at Korea Risk Group, think tanks, research universities, government entities, NGOs, media, academia, and other targets in the United States, Europe, and Asia.
Observed delivery methods include spear-phishing emails, OneDrive links to password-protected documents, macro-enabled Microsoft Office documents, and weaponized Office files delivered after rapport-building conversations. In one reported campaign, Kimsuky impersonated NK News and Chad O’Carroll, used the spoofed domain nknews[.]pro, and distributed malicious Office documents to deliver ReconShark. Proofpoint also noted ReconShark as a rare follow-on malware risk in TA427 benign-conversation campaigns, including cases where victims may access personal email from corporate devices.
ReconShark collects host reconnaissance data including running processes, battery details, hardware information, and deployed endpoint detection or security products. It uses WMI to query process and battery information and checks for security-related processes including ntrtscan.exe, mbam.exe, NortonSecurity.exe, and avpui.exe. It exfiltrates collected information via HTTP POST requests directly from memory without first writing the data to disk.
The malware can conditionally deploy additional payloads based on the security tools detected on the victim machine. Reported payload forms include VBS scripts, HTA scripts, batch scripts, DLLs, macro-enabled Office templates, and modified LNK files. ReconShark uses simple string encryption to hinder static detection, can download payloads directly with curl or stage them through LNK files and Office templates, modifies LNK files for msedge.exe, chrome.exe, outlook.exe, whale.exe, and firefox.exe to launch legitimate applications alongside malicious code, and replaces %AppData%\Microsoft\Templates\Normal.dotm with a malicious template from its C2 server. Later-stage payloads were observed creating %AppData%\1 containing ss or sss, possibly as execution markers.
Reported infrastructure and indicators associated with ReconShark campaigns include the C2 domain staradvertiser[.]store, which resolved to 162.0.209[.]27; the phishing and credential theft domain nknews[.]pro; and related Kimsuky infrastructure including yonsei[.]lol, rfa[.]ink, mitmail[.]tech, and newshare[.]online. Additional reported artifacts include the lure document SHA1 86a025e282495584eabece67e4e2a43dca28e505 and malicious macro SHA1 c8f54cb73c240a1904030eb36bb2baa7db6aeb01.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For example, we recently revealed the group’s distribution of ReconShark through macro-enabled Office documents.
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky
19 distinct techniques documented for this family, organized by ATT&CK tactic.
"The threat actors conduct extensive spearphishing operations, using typosquatting or domains thematically aligned with their target."
"...often involves malicious Hangul Word Processing (HWP) documents as a delivery mechanism... evolved its capabilities to include... Microsoft Word and PDF documents."
Ongoing campaigns use a new malware component we call ReconShark, which is actively delivered to specifically targeted individuals through spear-phishing emails, OneDrive links leading to document downloads... In the malicious emails, Kimsuky entices the target to open a link to download a password-protected document. Most recently, they made use of Microsoft OneDrive to host the malicious document for download.
Similar to previous BabyShark variants, ReconShark relies on Windows Management Instrumentation (WMI) to query process and battery information.
In addition to exfiltrating information, ReconShark deploys further payloads in a multi-stage manner that are implemented as scripts (VBS, HTA, and Windows Batch)...
ReconShark deploys further payloads in a multi-stage manner that are implemented as scripts (VBS, HTA, and Windows Batch)...
The lure documents Kimsuky distributes contain Microsoft Office macros that activate on document close. | ReconShark deploys further payloads in a multi-stage manner that are implemented as scripts (VBS, HTA, and Windows Batch)...
ReconShark functions as a reconnaissance tool... ReconShark checks for the presence of a broad set of processes associated with detection mechanisms, such as ntrtscan.exe, mbam.exe, NortonSecurity.exe, and avpui.exe.
22 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ReconShark is a Kimsuky reconnaissance malware component delivered via malicious Office macros. It profiles infected systems by collecting running process information, battery details, and endpoint detection products, exfiltrates that data via HTTP POST, and conditionally deploys additional payloads including VBS, HTA, batch scripts, Office templates, and DLLs. It also modifies LNK files and replaces Normal.dotm to achieve further payload execution and persistence-like compromise of Microsoft Word.
Custom malware previously distributed by Kimsuky as part of reconnaissance campaigns to enable subsequent attacks.
ReconShark is reconnaissance malware used by Kimsuky and delivered via password-protected weaponized Office documents. It exfiltrates information useful for follow-on precision attacks, including deployed detection mechanisms and hardware information.
Referenced as a malware payload that TA427 may deploy in rare cases after establishing trust via extended email conversations, potentially to compromise a corporate device when a victim checks personal email on it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.