Kimsuky Targets Recruiters and Crypto Users with Spear-Phishing Campaigns
Article Content
- •Kimsuky launched four spear-phishing campaigns in early 2026.
- •Targets include recruiters, crypto users, and defense officials.
- •Attack methods involve LNK and JSE files as lures.
In early 2026, the North Korea-linked Kimsuky threat group executed at least four spear-phishing campaigns targeting recruiters, cryptocurrency users, developers, defense personnel, and academic administrators. The campaigns utilized LNK and JSE files as lures, employing various themes to deceive victims. The attacks are part of a broader strategy to gather intelligence and exploit sensitive information from diverse sectors. Specific details on the tools used and the exact number of victims remain undisclosed, but the campaigns are characterized by their targeted nature and the involvement of a state-sponsored actor. As of May 19, 2026, the campaigns are ongoing, and organizations in the affected sectors are advised to enhance their security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Kimsuky in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
New ScreenConnect Flaw Enables Malware Spread via Rogue Clients ConnectWise has identified a critical vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments. The flaw, which impacts file transfer functionality, allows attackers to deploy rogue ScreenConnect clients that spread malware to connected systems. This malware is propagated through…