#kimsuky — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #kimsuky, aggregated by home.social.
-
Kimsuky AI operations reveal a North Korea threat actor testing local LLMs. Suspected state hackers are building new capabilities to automate phishing.
#Kimsuky #CyberSecurity #LLM #NorthKorea #ThreatActor #Genians
https://securityonline.info/kimsuky-ai-operations/?utm_source=mastodon&utm_medium=jetpack_social
-
Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
The Kimsuky threat group has integrated artificial intelligence capabilities into its attack operations, establishing local large language model environments using Ollama, GPT4All, and Msty. Evidence indicates the group is accumulating technologies to incorporate AI across attack operations, including AI-generated decoy documents and retrieval-augmented generation for document analysis. The campaign, dubbed Operation GitPower, continues targeting foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks utilize malicious LNK files contained in ZIP archives, executing obfuscated PowerShell scripts that abuse Git-based repositories as command-and-control infrastructure. The group distributes encrypted AsyncRAT payloads disguised as image files through GitHub. Linguistic indicators including North Korean vocabulary patterns such as "싸이트", "가입리력", and "로출되였는지" support attribution to North Korean state-sponsored operations under the Reconnaissance General Bureau.
Pulse ID: 6a79d612a1f9e2ac4e744aa8
Pulse Link: https://otx.alienvault.com/pulse/6a79d612a1f9e2ac4e744aa8
Pulse Author: AlienVault
Created: 2026-08-10 13:45:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #GitHub #InfoSec #Kimsuky #Korea #LNK #Military #NorthKorea #OTX #OpenThreatExchange #PowerShell #RAT #UK #ZIP #bot #AlienVault
-
Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT
Indicators extracted from public reporting. Source: https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
Pulse ID: 6a79ac473fe6b48d51cf0725
Pulse Link: https://otx.alienvault.com/pulse/6a79ac473fe6b48d51cf0725
Pulse Author: CyberHunter_NL
Created: 2026-08-10 10:47:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AsyncRAT #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #Kimsuky #OTX #OpenThreatExchange #RAT #RCE #UK #bot #CyberHunter_NL
-
Pulse ID: 6a604e212939fdf9ebc7c1f2
Pulse Link: https://otx.alienvault.com/pulse/6a604e212939fdf9ebc7c1f2
Pulse Author: Tr1sa111
Created: 2026-07-22 04:59:13Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Kimsuky #Korea #OTX #OpenThreatExchange #UK #bot #Tr1sa111
-
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
Pulse ID: 6a5e7a9e8b20b763327b0d2d
Pulse Link: https://otx.alienvault.com/pulse/6a5e7a9e8b20b763327b0d2d
Pulse Author: AlienVault
Created: 2026-07-20 19:44:30Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Google #HTTP #ICS #InfoSec #Kimsuky #Korea #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #Proxy #RAT #SouthKorea #SpearPhishing #UK #Vulnerability #bot #AlienVault
-
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
#Kimsuky #HttpSpy
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant -
Interesting technique. Obfuscates its string decoder inside android namespace "com .google .android .material .timepicker". That helper XOR-decodes which then concatenates into the C2: http://95.164.86[.]148/dash/index[.]php. #kimsuky
-
North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities
#Kimsuky
https://www.ic3.gov/CSA/2026/260108.pdf -
FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes https://www.securityweek.com/fbi-north-korean-spear-phishing-attacks-use-malicious-qr-codes/ #Malware&Threats #spear-phishing #NorthKorea #quishing #Kimsuky #QRcode #FBI
-
📬 Zehntausende ASUS-Router sind unter fremder Kontrolle
#Cyberangriffe #ITSicherheit #AiCloud #AsusRouter #AyySSHush #Kimsuky #Lazarus #ORBKnoten #WrtHug https://sc.tarnkappe.info/90a693 -
Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/ #ScamsandFraud #Cybersecurity #GoogleFundHub #CyberAttack #NorthKorea #SouthKorea #KakaoTalk #Security #Android #Malware #Kimsuky #APT37 #Konni
-
New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
#Kimsuky #EndClientRAT
https://www.0x0v1.com/endclientrat/ -
New Kimsuky Malware “EndClient RAT”: First Technical Report and IOCs
-
Generative-AI deepfakes + runtime command reconstruction = AV bypass. Kimsuky used ChatGPT images + environment-variable slicing to assemble malicious PowerShell/AutoIt chains and persist via scheduled tasks.
Recommend EDR behavioral rules for script reconstruction, scheduled-task anomalies, and staged HTTP fetch chains. Discuss & follow @technadu
#CyberSecurity #AI #Deepfakes #Phishing #EDR #ThreatIntel #Kimsuky #InfoSec
-
🇰🇵 Severokorejská skupina Kimsuky využívá ChatGPT k výrobě falešných průkazů pro phishing.
🇰🇵 The North Korean group Kimsuky uses ChatGPT to produce fake IDs for phishing.
-
North Korea’s #Kimsuky hackers are using AI-generated fake military IDs, reportedly created with ChatGPT, to lure victims in their latest phishing campaign.
Read: https://hackread.com/north-korea-kimsuky-group-ai-generated-military-ids/
-
Kimsuky Hackers’ Playbook Uncovered in Exposed ‘Kim’ Data Dump https://gbhackers.com/kimsuky-hackers/ #CyberSecurityNews #cybersecurity #Kimsuky
-
How the "Kim" dump exposed North Korea's credential theft playbook
#HackerNews #KimDump #NorthKorea #CredentialTheft #CyberSecurity #HackerNews #Kimsuky
-
Inside the Kimsuky Leak: How the “Kim” Dump Exposed North Korea’s Credential Theft Playbook
#Kimsuky
https://dti.domaintools.com/inside-the-kimsuky-leak-how-the-kim-dump-exposed-north-koreas-credential-theft-playbook/ -
🔥The "Kim" leak is an intelligence goldmine.
For analysts: We’ve got an unprecedented look into a DPRK threat actor's playbook. This isn't just about known tactics like credential theft and phishing. Our analysis shows a strategic pivot to include Taiwanese developer and government networks, revealing a clear geographical expansion of North Korea's cyber interests.
For defenders: We've mapped the full scope of this threat—from custom Linux rootkits to particular targets like PKI infrastructure and specific tools like NASM and ocrmypdf. Our report provides defensive recommendations and specific Indicators of Compromise (IOCs), so your team can detect and block this persistent, infrastructure-centric campaign.
Get the full technical breakdown and all the IOCs in our new post.
#ThreatIntelligence #Cybersecurity #NationStateAPT #Kimsuky #ThreatAnalysis #DFIR #InfoSec
-
Haktywiści przejmują komputer hakera działającego na zlecenie rządu Korei Północnej. Kulisy działania północnokoreańskich grup APT
Na początku 2025 r. dwóch hakerów posługujących się pseudonimami “Saber” oraz “cyb0rg” (ich tożsamość nie jest znana) uzyskali dostęp do infrastruktury, wyróżniającej się nietypowym zestawem narzędzi hakerskich. Postanowili dokładnie przeanalizować zawartość systemu oraz śledzić działania hakera, w celu ustalenia jak najwięcej szczegółów dotyczących jego aktywności. TLDR: Jak to wszystko się...
#WBiegu #Apt43 #Awareness #Chiny #Haktywizm #Kimsuky #Korea #Szpiegostwo
-
The #Kimsuky divergences in #ToyBox append a new command category in toys/android/ with the following options:
- getenforce / setenforce -> Query and modify SELinux enforcement
- restorecon / runcon -> Reset or run processes under SELinux contexts
- sendevent -> Generate low-level input events (touch/keys)
- log, logwrapper -> Interface with Android’s logging system
- load_policy -> Load SELinux policiesAlso include GN/Ninja integration (Google’s build system) for AOSP devices.
My guess is most likely used in their Android malware development
-
Hakerzy z Korei Północnej prowadzą nową kampanię cyber szpiegowską. Na celowniku placówki dyplomatyczne
Badacze z Trelix Advanced Research Center wykryli nową kampanię cyber szpiegowską wymierzoną w placówki dyplomatyczne w różnych regionach Korei Południowej. Od marca do lipca bieżącego roku zaobserwowano ponad 19 ataków spear-phishingowych, której celem były ambasady dyplomatyczne zlokalizowane na całym świecie. Za atakiem stoi prawdopodobnie ta sama grupa APT. Treści wiadomości...
#WBiegu #Apt #Apt43 #Awareness #Chiny #Github #Kimsuky #Korea #Szpiegowstwo #Xenorat
-
The Coordinated Embassy Hunt: Unmasking the DPRK-linked GitHub C2 Espionage Campaign
#Kimsuky
https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/ -
"#Kimsuky, you are not a hacker. You are driven by financial greed, to enrich your leaders, and to fulfill their political agenda. You steal from others and favour your own. You value yourself above the others: You are morally perverted. You hack for all the wrong reasons." https://data.ddosecrets.com/APT%20Down%20-%20The%20North%20Korea%20Files/phrack-apt-down-the-north-korea-files.pdf
-
Zwei Hacker haben den Rechner eines nordkoreanischen Spions geknackt und tiefe Einblicke in die Arbeitsweise von #Kimsuky gewonnen. Der Geheimdienst-Hacker arbeitete offenbar im geregelten 9-17-Uhr-Büroalltag. https://winfuture.de/news,152900.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia