The Kimsuky group, also known as APT43, compromised South Korean collaborative-work software vendors and their customers in a campaign carried out in 2025 and early 2026. This North Korean hacking group has a history of targeting the corporate infrastructure of South Korean companies and government entities for intelligence gathering.
Researchers at ENKI WhiteHat observed one case where hackers compromised a groupware vendor through an externally accessible mail server. This was achieved by installing malware via a remote code execution vulnerability. Another vendor was breached through social engineering of an employee, leading to the deployment of remote access tools on their PC.
After gaining initial access, the Kimsuky hackers deployed previously identified malware, Gomir, alongside new malware variants. They moved laterally within the compromised networks to steal customer server information from a vendor, which was then used to target the vendor's customers. Gomir was subsequently detected on a server belonging to one of the compromised vendor's SaaS customers.
The attackers also tampered with the login pages of compromised vendors to harvest employee credentials. ENKI noted that the lack of multifactor authentication contributed to these compromises.
The Kimsuky group is known for conducting intelligence gathering campaigns on behalf of Pyongyang. The U.S. government sanctioned the group in 2023 for using spear-phishing to target individuals in government, research centers, think tanks, academic institutions, and news media organizations. In 2024, AhnLab SEcurity Intelligence Center documented a Kimsuky campaign targeting small South Korean businesses with malware.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The North Korean Kimsuky group (APT43) compromised South Korean collaborative-work software vendors and subsequently breached their customers in a campaign spanning 2025 and early 2026. The attacks involved remote code execution, social engineering, and malware deployment to steal customer server information and employee credentials, highlighting persistent state-sponsored supply chain threats.