logo

North Korea's Kimsuky Taps Trusted Platforms to Attack South Korea

ID: 6c966665-c144-53a7-ba0f-8742e31ed020

STIX ID: report--6c966665-c144-53a7-ba0f-8742e31ed020

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-02-19

Date Updated: 2026-05-05

Author: Robert Lemos, Contributing Writer

...
...

A North Korea-linked APT (Kimsuky) ran a DEEP#DRIVE phishing campaign that tricked targets into executing a zipped shortcut which collected system configuration data, uploaded it to Dropbox using OAuth-protected folders, and fetched additional PowerShell/.NET payloads; researchers observed signs of thousands of configuration files and evidence of lateral movement, indicating large-scale espionage-focused operations with improved OPSEC and some financial targeting of cryptocurrency users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.