North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
ID: b970c7a9-f923-5122-a53d-c3028687c7de
STIX ID: report--b970c7a9-f923-5122-a53d-c3028687c7de
Feed Name: GBHackers
Kimsuky operators conducted a targeted spear-phishing campaign in South Korea and Japan using OneDrive-hosted ZIPs containing malicious LNK files that drop VBE/PowerShell payloads, establish scheduled-task persistence (e.g., Chrome_Update and AnyDesk loaders), deploy legitimate remote-access tools (AnyDesk, Chrome Remote Desktop) as covert backdoors, and steal email and Gmail data via collectors, a malicious Chrome extension, and an in-memory keylogger; the report includes IOCs and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
