New Kimsuky campaign compromised South Korean software vendors
ID: 9b05bab8-3858-503f-9caf-785ac89bc014
STIX ID: report--9b05bab8-3858-503f-9caf-785ac89bc014
Feed Name: The Record from Recorded Future News
Threat Score
North Korean APT Kimsuky (APT43) carried out a 2025–2026 supply-chain style campaign against South Korean collaborative-work software vendors, exploiting an externally accessible mail-server RCE and social-engineering to deploy Gomir and new malware variants, move laterally, steal customer server data, and harvest employee credentials via tampered login pages; lack of multifactor authentication aided the compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
