DriveTroy is a malware family tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed July 23, 2026; most recent activity July 24, 2026.
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…