
Kimsuky's Zero-Import 'svchow.dll' Evades Sandboxes in Espionage Campaign
A DPRK-aligned Kimsuky campaign deployed a zero-import PE32 DLL masquerading as "svchow.dll" to evade automated sandboxes. The espionage implant uses dynamic API resolution and debug detection, routing C2 through a single .kr domain with a PHP staging path.
A 112 KB Windows DLL carrying zero static imports — not a single function name visible in its import table — is circulating as "svchow.dll," a one-character typosquat of the legitimate svchost.dll, planted in the user-writable AppData\Local directory of compromised machines. The payload's combination of dynamic API resolution, debug-environment detection, and long-sleep delays split automated sandbox verdicts cleanly: one engine flagged it as malware, the other returned CLEAN.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read