New Kimsuky campaign compromised South Korean software vendors

North Korean hackers successfully targeted South Korean collaborative-work software vendors before breaching the suppliers’ customers, threat researchers have found.
The campaign by the Kimsuky group, also known as APT43, was carried out in 2025 and early 2026. The group has in the past gone after the corporate infrastructure of South Korean companies, as well as government entities.
In one case observed by researchers at the South Korean cybersecurity company ENKI WhiteHat, the hackers compromised a groupware vendor through an externally accessible mail server by installing malware through a remote code execution vulnerability.
Another vendor was compromised through social engineering of an employee and the subsequent deployment of remote access tools on their PC, the researchers said.
After gaining initial access to the unspecified vendors, the Kimsuky hackers deployed a previously seen malware called Gomir as well as new malware variants. They “aggressively” moved laterally and were able to steal customer server information from a vendor in order to target the company’s customers. The researchers detected Gomir installed on a server belonging to one of the compromised vendor’s SaaS customers.
They also tampered with the login pages of compromised vendors, allowing them to harvest employee credentials. ENKI noted that the lack of multifactor authentication opened the door for compromise.
Kimsuky is known for carrying out intelligence gathering campaigns on behalf of Pyongyang and was sanctioned in 2023 by the U.S. government for using “spear-phishing to target individuals employed by government, research centers, think tanks, academic institutions, and news media organizations.” Researchers at AhnLab SEcurity Intelligence Center in 2024 documented a Kimsuky campaign targeting small South Korean businesses with malware.
References in this story
- Analysis of Kimsuky www.enki.co.kr Analysis of Kimsuky
- North Korea-linked hackers target embassies in Seoul in new espionage campaign therecord.media North Korea-linked hackers were seen targeting more than a dozen embassies in Seoul with phishing emails.
- US sanctions North Korean ‘Kimsuky’ hackers after surveillance satellite launch therecord.media The U.S. partnered with several nations in the Pacific to hand down sanctions on North Korea — particularly the country’s Kimsuky cyber espionage group — after the country launched a surveillance satellite last week.
- SmallTiger Malware Used in Attacks Against South Korean Businesses (Kimsuky and Andariel) - ASEC asec.ahnlab.com SmallTiger Malware Used in Attacks Against South Korean Businesses (Kimsuky and Andariel) ASEC
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your business.
- James Reddick (@jredd66) on X twitter.com Audio and print journalist in Boston. Currently editing @therecord_media. Bylines: @capradio @mmfa @snapjudgment Previously in Cambodia @phnompenhpost



