Socprime
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
Article Content
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for command-and-control operations, enabling lateral movement to customer systems. Initial access was gained through remote code execution vulnerabilities and spear-phishing tactics. The campaign compromised at least two vendors, with attackers modifying login pages to harvest credentials. The ENKI WhiteHat report provides detailed analysis and Indicators of Compromise (IoCs) for detection. This operation reflects Kimsuky's ongoing focus on South Korean corporate infrastructure, leveraging previously undocumented malware. The attack's impact extends to downstream customers, potentially affecting numerous organizations reliant on the compromised groupware platforms.
Key Points: • Kimsuky exploited vulnerabilities in South Korean groupware vendors to deploy BirdTroy and DriveTroy. • The attackers used Google Drive for command-and-control, evading traditional security measures. • Credential harvesting was achieved by tampering with groupware login pages, lacking multi-factor authentication.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.