Socprime
Kimsuky Exploits Remote Access Tools and AI in Espionage Campaign
Article Content
Kimsuky threat actors are conducting spear-phishing campaigns targeting South Korea and Japan, utilizing OneDrive-hosted LNK files to deliver malware. The malware establishes persistence through scheduled tasks and retrieves PowerShell scripts to exfiltrate sensitive data, including emails and keystrokes. Attackers employ legitimate remote control tools like Chrome Remote Desktop and AnyDesk to maintain access, blending in with normal administrative activities. A malicious Chrome extension has been identified that collects Gmail data, indicating the use of generative AI in its development. Security experts recommend caution with LNK files from unknown sources and regular audits of installed software for unauthorized remote access tools. Organizations are advised to monitor for suspicious scheduled tasks and unexpected processes related to AnyDesk. The threat remains active and poses significant risks to targeted organizations.
Key Points: • Kimsuky uses spear-phishing with LNK files to deliver malware. • Legitimate tools like Chrome Remote Desktop and AnyDesk are exploited for access. • A malicious Chrome extension collects Gmail data, potentially using generative AI.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.