logo

It's 2024 and North Korea's Kimsuky gang is exploiting Windows Help files

ID: e8f59851-c85d-50d5-9aa0-962276eeec51

STIX ID: report--e8f59851-c85d-50d5-9aa0-962276eeec51

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2024-03-21

Date Updated: 2026-04-26

Author: Simon Sharwood

...
...

Rapid7 reports that North Korean APT Kimsuky (aka Black Banshee/Thallium/APT43) is running a campaign using poisoned CHM files (and ISO/VHD/ZIP/RAR containers) to deliver VBScript-based infostealers that collect machine and document data and establish registry persistence; Rapid7 published indicators of compromise and attributes the activity to Kimsuky with moderate confidence, identifying South Korea as the primary target and signs of activity in Germany.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.