N. Korea-linked Kimsuky Shifts to Compiled HTML Help Files in Ongoing Cyberattacks
ID: 6e95d845-9cfb-5d3c-bc53-7b1395dfe047
STIX ID: report--6e95d845-9cfb-5d3c-bc53-7b1395dfe047
Feed Name: The Hacker News
Threat Score
Kimsuky, a North Korea-linked APT, is actively shifting tactics to use CHM files (delivered within ISOs, VHDs, ZIP/RAR) and other weaponized documents to execute JavaScript/VBScript that establishes persistence and fetches next-stage payloads (Endoor backdoor, Troll Stealer) for data theft; operations target South Korea and international organizations, reuse code and tools, and may incorporate generative AI to support phishing or coding.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
