Attackers exploited ConnectWise ScreenConnect vulnerabilities CVE-2024-1708 and CVE-2024-1709 to gain access to exposed systems and deploy a malware sample that Kroll said closely resembles BABYSHARK, a family previously associated with North Korea-linked Kimsuky activity. In the observed intrusion, the actor abused the ScreenConnect setup wizard for initial access, launched mshta.exe, and retrieved a heavily obfuscated VBScript payload designed to generate unique code, junk content, and changing second-stage URLs on each download.
The malware gathered host, user, network, process, and security-tool information, altered Microsoft Office VBA warning registry settings, and used certutil to encode stolen data into PEM format before exfiltrating it to command-and-control infrastructure. It also established persistence through a scheduled task that executed VBScript from an Alternate Data Stream and checked a unique URL every minute for follow-on code, behavior consistent with selective payload delivery. The activity aligns with earlier reporting on Kimsuky’s evolving reconnaissance tradecraft and prior BABYSHARK operations targeting policy and national security organizations.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Kroll publicly described the attempted compromise, including the use of mshta-delivered obfuscated VBScript, host reconnaissance, registry changes to lower Office macro protections, data exfiltration, and persistence via a scheduled task named Uso1Cache. The report also noted the malware used changing payload URLs and likely selective follow-on delivery from command-and-control infrastructure.
SentinelOne published research on a new global Kimsuky campaign that showed the group's reconnaissance capabilities evolving, providing prior context for malware and tradecraft later compared to BABYSHARK activity.
Kroll detected and stopped an attempted intrusion in which a threat actor exploited ConnectWise ScreenConnect vulnerabilities CVE-2024-1708 and CVE-2024-1709 to access a victim workstation and deploy a new malware sample. Based on code and behavioral overlap, Kroll assessed the malware was likely a BABYSHARK variant previously associated with Kimsuky.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
kroll.com
Open sourcesentinelone.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.