Socprime
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for command-and-control operations, enabling lateral movement to customer systems. Initial access was gained through remote code execution vulnerabilities and spear-phishing tactics. The campaign compromised at least two vendors, with attackers modifying login pages to harvest credentials. The ENKI WhiteHat report provides detailed analysis and Indicators of Compromise (IoCs) for detection. This operation reflects Kimsuky's ongoing focus on South Korean corporate infrastructure, leveraging previously undocumented malware. The attack's impact extends to downstream customers, potentially affecting numerous organizations reliant on the compromised groupware platforms.
Key Points: • Kimsuky exploited vulnerabilities in South Korean groupware vendors to deploy BirdTroy and DriveTroy. • The attackers used Google Drive for command-and-control, evading traditional security measures. • Credential harvesting was achieved by tampering with groupware login pages, lacking multi-factor authentication.