Socprime Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
Article Content
- •Kimsuky exploited vulnerabilities in South Korean groupware vendors to deploy BirdTroy and DriveTroy.
- •The attackers used Google Drive for command-and-control, evading traditional security measures.
- •Credential harvesting was achieved by tampering with groupware login pages, lacking multi-factor authentication.
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for command-and-control operations, enabling lateral movement to customer systems. Initial access was gained through remote code execution vulnerabilities and spear-phishing tactics. The campaign compromised at least two vendors, with attackers modifying login pages to harvest credentials. The ENKI WhiteHat report provides detailed analysis and Indicators of Compromise (IoCs) for detection. This operation reflects Kimsuky's ongoing focus on South Korean corporate infrastructure, leveraging previously undocumented malware. The attack's impact extends to downstream customers, potentially affecting numerous organizations reliant on the compromised groupware platforms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track APT41, ClickFix and Korea Hydro And Nuclear Power in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
China-Linked QTFY Group Targets Critical Infrastructure with Advanced Exploits The Joint Cybersecurity Advisory JCSA-20260826-01, released on August 26, 2026, details ongoing activities by the China-linked hacking group QTFY, attributed to Nanjing Xinjiuwei Network Technology Co. Active since 2018, QTFY employs platforms like QScan and QTRouter to exploit vulnerabilities in critical…
AI-Generated Exploits Target Siemens PLCs in Critical Infrastructure On August 19, 2026, U.S. agencies issued a joint advisory confirming that threat actors are using AI-generated exploitation scripts to target Siemens S7 Series PLCs across critical infrastructure sectors, including water, energy, and manufacturing. The advisory, co-signed by the NSA, CISA, FBI, DOE, and EPA…