Kimsuky APT Data Leak – GPKI Certificates, Rootkits and Cobalt Strike Personal Uncovered
ID: 16d4b3e4-93d5-56dd-9efa-9c6da4293d8c
STIX ID: report--16d4b3e4-93d5-56dd-9efa-9c6da4293d8c
Feed Name: cybersecurityNews.com
Kimsuky APT operator files leaked on a dark-web forum revealed Deepin VM images and a public VPS containing browser histories, auth logs, thousands of stolen GPKI certificates, a Java certificate-cracking tool, and bespoke malware — notably a Tomcat Kernel Rootkit that hooks network calls and a customized Cobalt Strike beacon using HTTP over port 8172. The artifacts provide direct insight into active spear-phishing campaigns against South Korean government entities and demonstrate advanced persistence and evasion techniques enabling credential theft, document signing impersonation, and stealthy C2 access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
