Inside the Kimsuky Breach – Exposed GPKI Certificates, Stealth Rootkits, and Cobalt Strike Operations
ID: e426cd17-f488-5a4e-88d8-4a97c52fdb78
STIX ID: report--e426cd17-f488-5a4e-88d8-4a97c52fdb78
Feed Name: Cyber Press
Threat Score
A major data dump attributed to North Korea’s Kimsuky (APT43) appeared on a dark web forum, leaking VM images, VPS dumps, phishing kits, and thousands of credentials — notably thousands of stolen South Korean GPKI certificates — along with custom malware (Tomcat Kernel Rootkit, SpawnChimera), a tailored Cobalt Strike Beacon, and exploit packages for Ivanti appliances, providing unprecedented visibility into the group’s tooling, credential-harvesting tactics, and operational mistakes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
