home.social

#kimsuky — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kimsuky, aggregated by home.social.

fetched live
  1. North Korea Deploys AI-Built Chrome Extension to Steal Gmail

    Kimsuky hackers used an AI-generated Chrome extension that automatically exfiltrates Gmail messages and attachments to North Korean servers

    pulseofnations.lol/north-korea

    #AI #ChromeExtension #Gmail #Kimsuky #NorthKorea #Phishing #StateSponsored

  2. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Pulse ID: 6a8d193e166f33d196fc97b8
    Pulse Link: otx.alienvault.com/pulse/6a8d1
    Pulse Author: Tr1sa111
    Created: 2026-08-25 04:25:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #InfoSec #Kimsuky #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  3. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Pulse ID: 6a87f297285ce48e4e1d19fc
    Pulse Link: otx.alienvault.com/pulse/6a87f
    Pulse Author: Tr1sa111
    Created: 2026-08-21 06:39:19

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #CyberSecurity #InfoSec #Kimsuky #OTX #OpenThreatExchange #UK #bot #Tr1sa111

  4. Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

    Kimsuky conducted spear phishing campaigns against South Korean and Japanese targets during the first half of 2026, distributing LNK malware through OneDrive share links. The malicious files established scheduled tasks that periodically fetched PowerShell scripts from command-and-control servers to profile systems, exfiltrate Thunderbird and Outlook email data, and log keystrokes. The threat actor installed legitimate remote control software including Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain multiple access channels. A malicious Chrome extension designed to steal Gmail data exhibited characteristics of AI-generated code, featuring Korean comments, debug strings, and Unicode emoji throughout. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to impede tracking efforts.

    Pulse ID: 6a873495a873c0ec3c6d9880
    Pulse Link: otx.alienvault.com/pulse/6a873
    Pulse Author: AlienVault
    Created: 2026-08-20 17:08:37

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AnyDesk #Asia #Chrome #ChromeExtension #CyberSecurity #EDR #Email #ICS #InfoSec #Japan #Kimsuky #Korea #LNK #Malware #OTX #OpenThreatExchange #Outlook #Phishing #PowerShell #RAT #SouthKorea #SpearPhishing #UK #bot #AlienVault

  5. Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM

    The Kimsuky threat group has integrated artificial intelligence capabilities into its attack operations, establishing local large language model environments using Ollama, GPT4All, and Msty. Evidence indicates the group is accumulating technologies to incorporate AI across attack operations, including AI-generated decoy documents and retrieval-augmented generation for document analysis. The campaign, dubbed Operation GitPower, continues targeting foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks utilize malicious LNK files contained in ZIP archives, executing obfuscated PowerShell scripts that abuse Git-based repositories as command-and-control infrastructure. The group distributes encrypted AsyncRAT payloads disguised as image files through GitHub. Linguistic indicators including North Korean vocabulary patterns such as "싸이트", "가입리력", and "로출되였는지" support attribution to North Korean state-sponsored operations under the Reconnaissance General Bureau.

    Pulse ID: 6a79d612a1f9e2ac4e744aa8
    Pulse Link: otx.alienvault.com/pulse/6a79d
    Pulse Author: AlienVault
    Created: 2026-08-10 13:45:54

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #GitHub #InfoSec #Kimsuky #Korea #LNK #Military #NorthKorea #OTX #OpenThreatExchange #PowerShell #RAT #UK #ZIP #bot #AlienVault

  6. Kimsuky Uses Local LLMs, AI-Generated Lures and GitHub C2 to Deploy AsyncRAT

    Indicators extracted from public reporting. Source: genians.co.kr/en/blog/threat_i

    Pulse ID: 6a79ac473fe6b48d51cf0725
    Pulse Link: otx.alienvault.com/pulse/6a79a
    Pulse Author: CyberHunter_NL
    Created: 2026-08-10 10:47:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AsyncRAT #CyberSecurity #GitHub #HTTP #HTTPS #InfoSec #Kimsuky #OTX #OpenThreatExchange #RAT #RCE #UK #bot #CyberHunter_NL

  7. Interesting technique. Obfuscates its string decoder inside android namespace "com .google .android .material .timepicker". That helper XOR-decodes which then concatenates into the C2: http://95.164.86[.]148/dash/index[.]php. #kimsuky

  8. North Korean Kimsuky Actors Leverage Malicious QR Codes in Spearphishing Campaigns Targeting U.S. Entities
    #Kimsuky
    ic3.gov/CSA/2026/260108.pdf

  9. Generative-AI deepfakes + runtime command reconstruction = AV bypass. Kimsuky used ChatGPT images + environment-variable slicing to assemble malicious PowerShell/AutoIt chains and persist via scheduled tasks.

    Recommend EDR behavioral rules for script reconstruction, scheduled-task anomalies, and staged HTTP fetch chains. Discuss & follow @technadu

    #CyberSecurity #AI #Deepfakes #Phishing #EDR #ThreatIntel #Kimsuky #InfoSec

  10. North Korea’s #Kimsuky hackers are using AI-generated fake military IDs, reportedly created with ChatGPT, to lure victims in their latest phishing campaign.

    Read: hackread.com/north-korea-kimsu

    #CyberSecurity #NorthKorea #Scam #Phishing #ChatGPT

  11. 🔥The "Kim" leak is an intelligence goldmine.

    For analysts: We’ve got an unprecedented look into a DPRK threat actor's playbook. This isn't just about known tactics like credential theft and phishing. Our analysis shows a strategic pivot to include Taiwanese developer and government networks, revealing a clear geographical expansion of North Korea's cyber interests.

    For defenders: We've mapped the full scope of this threat—from custom Linux rootkits to particular targets like PKI infrastructure and specific tools like NASM and ocrmypdf. Our report provides defensive recommendations and specific Indicators of Compromise (IOCs), so your team can detect and block this persistent, infrastructure-centric campaign.

    Get the full technical breakdown and all the IOCs in our new post.

    🔗dti.domaintools.com/inside-the

    #ThreatIntelligence #Cybersecurity #NationStateAPT #Kimsuky #ThreatAnalysis #DFIR #InfoSec

  12. Haktywiści przejmują komputer hakera działającego na zlecenie rządu Korei Północnej. Kulisy działania północnokoreańskich grup APT

    Na początku 2025 r. dwóch hakerów posługujących się pseudonimami “Saber” oraz “cyb0rg” (ich tożsamość nie jest znana) uzyskali dostęp do infrastruktury, wyróżniającej się nietypowym zestawem narzędzi hakerskich. Postanowili dokładnie przeanalizować zawartość systemu oraz śledzić działania hakera, w celu ustalenia jak najwięcej szczegółów dotyczących jego aktywności. TLDR: Jak to wszystko się...

    #WBiegu #Apt43 #Awareness #Chiny #Haktywizm #Kimsuky #Korea #Szpiegostwo

    sekurak.pl/haktywisci-przejmuj

  13. The #Kimsuky divergences in #ToyBox append a new command category in toys/android/ with the following options:

    - getenforce / setenforce -> Query and modify SELinux enforcement
    - restorecon / runcon -> Reset or run processes under SELinux contexts
    - sendevent -> Generate low-level input events (touch/keys)
    - log, logwrapper -> Interface with Android’s logging system
    - load_policy -> Load SELinux policies

    Also include GN/Ninja integration (Google’s build system) for AOSP devices.

    My guess is most likely used in their Android malware development