logo

North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access

ID: b970c7a9-f923-5122-a53d-c3028687c7de

STIX ID: report--b970c7a9-f923-5122-a53d-c3028687c7de

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

Author: Mayura Kathir

...
...

Kimsuky operators conducted a targeted spear-phishing campaign in South Korea and Japan using OneDrive-hosted ZIPs containing malicious LNK files that drop VBE/PowerShell payloads, establish scheduled-task persistence (e.g., Chrome_Update and AnyDesk loaders), deploy legitimate remote-access tools (AnyDesk, Chrome Remote Desktop) as covert backdoors, and steal email and Gmail data via collectors, a malicious Chrome extension, and an in-memory keylogger; the report includes IOCs and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.