Skip to content
ThreatCluster

Kimsuky Targets Recruiters and Crypto Users with Spear-Phishing Campaigns

First seen 19 May 2026, 19:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 20, 2026 at 19:06 UTC
  • Kimsuky launched four spear-phishing campaigns in early 2026.
  • Targets include recruiters, crypto users, and defense officials.
  • Attack methods involve LNK and JSE files as lures.

In early 2026, the North Korea-linked Kimsuky threat group executed at least four spear-phishing campaigns targeting recruiters, cryptocurrency users, developers, defense personnel, and academic administrators. The campaigns utilized LNK and JSE files as lures, employing various themes to deceive victims. The attacks are part of a broader strategy to gather intelligence and exploit sensitive information from diverse sectors. Specific details on the tools used and the exact number of victims remain undisclosed, but the campaigns are characterized by their targeted nature and the involvement of a state-sponsored actor. As of May 19, 2026, the campaigns are ongoing, and organizations in the affected sectors are advised to enhance their security measures.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 123d ago How this analysis works

Timeline

2026-05-19
Kimsuky campaigns reported
Kimsuky executed multiple spear-phishing campaigns targeting various sectors, including defense and cryptocurrency.
Gbhackers
2026-05-19
Kimsuky campaigns detailed
Cybersecuritynews reported on Kimsuky's spear-phishing tactics targeting recruiters and crypto investors.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track Kimsuky in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed