15/04/2026
We Dumped a Live Kimsuky C2 and Recovered Every Stage of the Kill Chain: CHM Dropper, VBScript Stager, PowerShell Keylogger
On April 11, 2026, we picked up a CHM file tagged Kimsuky from MalwareBazaar and walked the infrastructure. The C2 server at check.nid-log.com had directory listing enabled and was serving payloads to anyone who asked. We recovered the complete source code of all three attack stages before the actor...