logo

New Kimsuky campaign compromised South Korean software vendors

ID: 9b05bab8-3858-503f-9caf-785ac89bc014

STIX ID: report--9b05bab8-3858-503f-9caf-785ac89bc014

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

North Korean APT Kimsuky (APT43) carried out a 2025–2026 supply-chain style campaign against South Korean collaborative-work software vendors, exploiting an externally accessible mail-server RCE and social-engineering to deploy Gomir and new malware variants, move laterally, steal customer server data, and harvest employee credentials via tampered login pages; lack of multifactor authentication aided the compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.