ThreatCluster

Kimsuky Targets Recruiters and Crypto Users with Spear-Phishing Campaigns

First seen 19 May 2026, 19:25 UTC GbhackersCybersecuritynews 95% similarity 73

Article Content

Browse articles
ThreatCluster

In early 2026, the North Korea-linked Kimsuky threat group executed at least four spear-phishing campaigns targeting recruiters, cryptocurrency users, developers, defense personnel, and academic administrators. The campaigns utilized LNK and JSE files as lures, employing various themes to deceive victims. The attacks are part of a broader strategy to gather intelligence and exploit sensitive information from diverse sectors. Specific details on the tools used and the exact number of victims remain undisclosed, but the campaigns are characterized by their targeted nature and the involvement of a state-sponsored actor. As of May 19, 2026, the campaigns are ongoing, and organizations in the affected sectors are advised to enhance their security measures.

Key Points: • Kimsuky launched four spear-phishing campaigns in early 2026. • Targets include recruiters, crypto users, and defense officials. • Attack methods involve LNK and JSE files as lures.

ThreatCluster AI

Timeline

2026-05-19
Kimsuky campaigns reported
Kimsuky executed multiple spear-phishing campaigns targeting various sectors, including defense and cryptocurrency.
Gbhackers
2026-05-19
Kimsuky campaigns detailed
Cybersecuritynews reported on Kimsuky's spear-phishing tactics targeting recruiters and crypto investors.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story