logo

Inside the Kimsuky Breach – Exposed GPKI Certificates, Stealth Rootkits, and Cobalt Strike Operations

ID: e426cd17-f488-5a4e-88d8-4a97c52fdb78

STIX ID: report--e426cd17-f488-5a4e-88d8-4a97c52fdb78

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-08-25

Date Updated: 2026-04-19

Author: Priya

...
...

A major data dump attributed to North Korea’s Kimsuky (APT43) appeared on a dark web forum, leaking VM images, VPS dumps, phishing kits, and thousands of credentials — notably thousands of stolen South Korean GPKI certificates — along with custom malware (Tomcat Kernel Rootkit, SpawnChimera), a tailored Cobalt Strike Beacon, and exploit packages for Ivanti appliances, providing unprecedented visibility into the group’s tooling, credential-harvesting tactics, and operational mistakes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.