news.mlab.sh
Back to the feed
threat-intel

New Kimsuky campaign compromised South Korean software vendors

High
Summary

A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote code execution vulnerabilities to steal data and manipulate login pages, demonstrating a sophisticated and persistent intelligence-gathering operation.

North Korean hackers, specifically the Kimsuky group (APT43), conducted a multi-faceted campaign targeting South Korean software vendors between 2025 and early 2026. The campaign involved a combination of social engineering and exploiting vulnerabilities to gain access to vendor systems and subsequently their customers. Researchers at ENKI WhiteHat observed that one vendor was initially compromised through an externally accessible mail server, utilizing a remote code execution vulnerability to install malware.

Another vendor was compromised via social engineering, where an employee was tricked into installing remote access tools on their PC. Following initial access, Kimsuky deployed previously seen malware, Gomir, alongside new malware variants. The group aggressively moved laterally within the vendor’s network, ultimately stealing customer server information to target the vendor’s customers.

Researchers noted that a lack of multi-factor authentication significantly contributed to the compromise of several vendors. Kimsuky is known for conducting intelligence gathering operations on behalf of Pyongyang and was sanctioned in 2023 by the U.S. government for using spear-phishing to target individuals employed by government, research centers, think tanks, academic institutions, and news media organizations. The campaign highlights the group’s continued focus on targeting South Korean entities for intelligence purposes.

Read the full article at The Record