Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
ID: 6d7ed801-8708-5668-bf9b-278029adf304
STIX ID: report--6d7ed801-8708-5668-bf9b-278029adf304
Feed Name: ThreatCluster
Threat Score
Kimsuky targeted South Korean groupware vendors between late 2025 and early 2026, deploying new Linux backdoors named BirdTroy and DriveTroy that used Google Drive for command-and-control. Attackers gained initial access via remote code execution flaws and spear-phishing, modified login pages to harvest credentials, and moved laterally to downstream customers; the ENKI WhiteHat report includes detailed IoCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
