Kimsuky Exploits Remote Access Tools and AI in Espionage Campaign

Kimsuky Exploits Remote Access Tools and AI in Espionage Campaign

First seen 26 Aug 2026, 16:26 UTC CybersecuritynewsSocprime 72.0

Article Content

Browse articles
ThreatCluster

Kimsuky threat actors are conducting spear-phishing campaigns targeting South Korea and Japan, utilizing OneDrive-hosted LNK files to deliver malware. The malware establishes persistence through scheduled tasks and retrieves PowerShell scripts to exfiltrate sensitive data, including emails and keystrokes. Attackers employ legitimate remote control tools like Chrome Remote Desktop and AnyDesk to maintain access, blending in with normal administrative activities. A malicious Chrome extension has been identified that collects Gmail data, indicating the use of generative AI in its development. Security experts recommend caution with LNK files from unknown sources and regular audits of installed software for unauthorized remote access tools. Organizations are advised to monitor for suspicious scheduled tasks and unexpected processes related to AnyDesk. The threat remains active and poses significant risks to targeted organizations.

Key Points: • Kimsuky uses spear-phishing with LNK files to deliver malware. • Legitimate tools like Chrome Remote Desktop and AnyDesk are exploited for access. • A malicious Chrome extension collects Gmail data, potentially using generative AI.

Timeline

2026-08-24
Kimsuky espionage campaign reported
Cybersecuritynews reported Kimsuky using a Chrome extension to collect Gmail data through phishing emails.
Cybersecuritynews
2026-08-26
Kimsuky campaign details published
Socprime detailed Kimsuky's use of remote access tools and malware for data theft in Northeast Asia.
Socprime