beautypy refers to a Python backdoor delivered in a Kimsuky campaign using malicious Windows LNK files disguised as document shortcuts. In the reported infection chain, the LNK launches PowerShell, which creates a hidden folder at C:\windirr, drops intermediary XML/VBS/PS1 components, and establishes persistence via scheduled tasks with Google-themed names. A PowerShell stage collects host information including user domain, username, running processes, OS version, public IP, and antivirus details, exfiltrates that data via Dropbox, then retrieves and executes hh.bat. That BAT downloads ZIP fragments from quickcon.store, reconstructs and extracts an archive to C:\winii containing the XML scheduler file norton.db and the Python backdoor beauty.py, then registers a scheduled task named GoogleExtension{02-2032121-098} to execute C:\winii\beauty.py. The backdoor communicates with C2 server 45.95.186[.]232:8080, sends packets containing the string "HAPPY," and uses a custom 4096-byte protocol with magic bytes 0x99 0x0A 0xBD 0x99. Reported capabilities include remote shell/command execution, drive enumeration, directory listing, file upload and download, file deletion with random-data overwrite, execution of .exe, .bat, and .vbs files, and termination. ASEC attributed the activity to Kimsuky based on similarities in scheduled task naming, XML scheduler filenames, and reuse of decoy documents seen in prior Kimsuky operations. Observed related infrastructure included quickcon.store, qugesr[.]online, whaincloud[.]store, zoommet[.]site, and racswera[.]online.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
압축 파일 내부에는 XML 작업 스케줄러 파일(norton.db)과 파이썬 백도어 파일(beauty.py)이 포함되어 있다. ... hh.bat 파일은 GoogleExtension{02-2032121-098} 이라는 작업 스케줄러 이름으로 C:\winii\beauty.py 파일을 실행하도록 작업을 등록하며, 이를 통해 파이썬 백도어가 실행된다.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on the XML file, a scheduled task named Microsoft_Upgrade{10-9903-09-821392134} is registered.
Depending on the command code, it performs the following functions: Shell command execution
Once opened, the LNK file triggers a hidden PowerShell script that creates a concealed folder at C:\windirr... In the past, the attack flow moved from an LNK file to PowerShell and directly to a BAT file. In the recent version, the intermediate stage now runs through an XML file, a VBS file, a PS1 file, and finally a BAT file before reaching the payload.
After the LNK file is opened, the PowerShell script creates the hidden folder and drops three files: an XML task scheduler file ( sch_ha.db ), a VBS script ( 11.vbs ), and a PowerShell script ( pp.ps1 ). When the VBS file runs, it launches pp.ps1.
During analysis, actions such as collecting drive information, network configuration (via ipconfig), and running processes (via tasklist) were observed.
During analysis, actions such as collecting drive information, network configuration (via ipconfig), and running processes (via tasklist) were observed.
During analysis, actions such as collecting drive information, network configuration (via ipconfig), and running processes (via tasklist) were observed.
The backdoor sends a packet containing the string “ HAPPY ” to the C2 server at 45.95.186[.]232:8080 to signal successful infection.
The backdoor sends packets with the string “HAPPY” to the C2 server, 45.95.186[.]232:8080... communicates with a fixed-size (4096 bytes) custom protocol based on magic bytes
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python-based backdoor deployed by Kimsuky through a multi-stage LNK-to-PowerShell/XML/VBS/PS1/BAT infection chain. It establishes persistence via scheduled tasks, connects to a C2 server, sends a "HAPPY" packet to confirm infection, and allows remote command execution, file operations, and program execution on the victim system.
Python 기반 백도어로, C2 서버와 커스텀 프로토콜로 통신하며 쉘 명령 실행, 드라이브 조회, 디렉터리 조회, 파일 업로드/다운로드, 파일 삭제, BAT/VBS/EXE 실행 등의 기능을 수행한다.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.