logo

New DEEP#GOSU Malware Campaign Targets Windows Users with Advanced Tactics

ID: 9d248249-4248-51a5-9109-f28cfc628a09

STIX ID: report--9d248249-4248-51a5-9109-f28cfc628a09

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Securonix and reporting outlets detail a sophisticated DEEP#GOSU campaign linked to the North Korean APT Kimsuky that uses weaponized .LNK files in ZIP attachments to execute embedded PowerShell and VBScript, fetch additional modules from Dropbox/Google Docs, and deploy a TruRat .NET remote access trojan to perform keylogging, clipboard capture, reconnaissance and data exfiltration, with persistence via scheduled tasks and WMI; the report also contextualizes this activity with other state-linked campaigns and crypto-laundering by Lazarus/Andariel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.