APTMembers
APT

Kimsuky's Zero-Import 'svchow.dll' Evades Sandboxes in Espionage Campaign

A DPRK-aligned Kimsuky campaign deployed a zero-import PE32 DLL masquerading as "svchow.dll" to evade automated sandboxes. The espionage implant uses dynamic API resolution and debug detection, routing C2 through a single .kr domain with a PHP staging path.

Jun 30, 2026, 19:33 (UTC+9)Last seenJun 30, 2026Severity77ByCTX TeamActorKimsukyVelvet ChollimaIOC18MITRE26RegionsJO

A 112 KB Windows DLL carrying zero static imports — not a single function name visible in its import table — is circulating as "svchow.dll," a one-character typosquat of the legitimate svchost.dll, planted in the user-writable AppData\Local directory of compromised machines. The payload's combination of dynamic API resolution, debug-environment detection, and long-sleep delays split automated sandbox verdicts cleanly: one engine flagged it as malware, the other returned CLEAN.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence