← All stories
● Covered by 1 source · 1 reportHigh impact1 neutral

North Korean Kimsuky Group Compromises South Korean Software Vendors and Customers

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Kimsuky group targeted South Korean software vendors.
  • Compromised vendors led to breaches of their customers.
  • Methods included RCE, social engineering, and malware deployment.
  • Customer server information and employee credentials were stolen.

North Korean Kimsuky Group Targets South Korean Vendors

The Kimsuky group, also known as APT43, compromised South Korean collaborative-work software vendors and their customers in a campaign carried out in 2025 and early 2026. This North Korean hacking group has a history of targeting the corporate infrastructure of South Korean companies and government entities for intelligence gathering.

Attack Vectors and Compromise Methods

Researchers at ENKI WhiteHat observed one case where hackers compromised a groupware vendor through an externally accessible mail server. This was achieved by installing malware via a remote code execution vulnerability. Another vendor was breached through social engineering of an employee, leading to the deployment of remote access tools on their PC.

Post-Compromise Activities and Impact

After gaining initial access, the Kimsuky hackers deployed previously identified malware, Gomir, alongside new malware variants. They moved laterally within the compromised networks to steal customer server information from a vendor, which was then used to target the vendor's customers. Gomir was subsequently detected on a server belonging to one of the compromised vendor's SaaS customers.

The attackers also tampered with the login pages of compromised vendors to harvest employee credentials. ENKI noted that the lack of multifactor authentication contributed to these compromises.

Kimsuky's History and Sanctions

The Kimsuky group is known for conducting intelligence gathering campaigns on behalf of Pyongyang. The U.S. government sanctioned the group in 2023 for using spear-phishing to target individuals in government, research centers, think tanks, academic institutions, and news media organizations. In 2024, AhnLab SEcurity Intelligence Center documented a Kimsuky campaign targeting small South Korean businesses with malware.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The North Korean Kimsuky group (APT43) compromised South Korean collaborative-work software vendors and subsequently breached their customers in a campaign spanning 2025 and early 2026. The attacks involved remote code execution, social engineering, and malware deployment to steal customer server information and employee credentials, highlighting persistent state-sponsored supply chain threats.