logo

Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants

ID: 6d7ed801-8708-5668-bf9b-278029adf304

STIX ID: report--6d7ed801-8708-5668-bf9b-278029adf304

Feed Name: ThreatCluster

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

Kimsuky targeted South Korean groupware vendors between late 2025 and early 2026, deploying new Linux backdoors named BirdTroy and DriveTroy that used Google Drive for command-and-control. Attackers gained initial access via remote code execution flaws and spear-phishing, modified login pages to harvest credentials, and moved laterally to downstream customers; the ENKI WhiteHat report includes detailed IoCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.