Kimsuky Hacked South Korean Groupware Vendors With New Gomir Variants
ID: 2f9450b5-a99d-565d-b3e5-83fa88faa513
STIX ID: report--2f9450b5-a99d-565d-b3e5-83fa88faa513
Feed Name: securityonline.info
Threat Score
ENKI WhiteHat attributes an active Kimsuky campaign that breached two South Korean groupware vendors (Nov–Dec 2025), exfiltrated customer records, and deployed novel Linux backdoors (BirdTroy, DriveTroy) and proxy tooling to pivot into customer networks; the attackers used RCE and credential-harvesting (fake login pages), abused trusted services (Google Drive, HTTP/3 over QUIC) for C2, and left indicators and YARA rules in the full report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
