Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants

Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants

First seen 24 Jul 2026, 11:43 UTC SocprimeTechtimeswww.enki.co.krwww.security.comdope.security+2 85% similarity 77.0

Article Content

Browse articles
ThreatCluster

The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for command-and-control operations, enabling lateral movement to customer systems. Initial access was gained through remote code execution vulnerabilities and spear-phishing tactics. The campaign compromised at least two vendors, with attackers modifying login pages to harvest credentials. The ENKI WhiteHat report provides detailed analysis and Indicators of Compromise (IoCs) for detection. This operation reflects Kimsuky's ongoing focus on South Korean corporate infrastructure, leveraging previously undocumented malware. The attack's impact extends to downstream customers, potentially affecting numerous organizations reliant on the compromised groupware platforms.

Key Points: • Kimsuky exploited vulnerabilities in South Korean groupware vendors to deploy BirdTroy and DriveTroy. • The attackers used Google Drive for command-and-control, evading traditional security measures. • Credential harvesting was achieved by tampering with groupware login pages, lacking multi-factor authentication.

ThreatCluster AI

Timeline

2025-11-01
Initial compromise of groupware vendor A
Kimsuky exploited a remote code execution vulnerability in an externally accessible mail server to install Gomir.
Article 1
2025-12-01
Compromise of groupware vendor B confirmed
Kimsuky used spear-phishing to gain access to an employee's PC, deploying DriveTroy.
Article 2
2026-07-20
ENKI WhiteHat publishes analysis
ENKI WhiteHat released a report detailing Kimsuky's use of BirdTroy and DriveTroy in their campaign against South Korean vendors.
Article 1
2026-07-24
Public awareness raised about Kimsuky campaign
Multiple cybersecurity firms reported on the Kimsuky campaign, emphasizing the need for enhanced security measures.
Article 2

Community

Browse all →