Springtail

2024-03-20 • SymantecNew DEEP#GOSU campaign attributed to Springtail A…

Springtail is Symantec’s designation for the North Korean espionage group also known as Kimsuky. The group first drew public attention in 2014 after South Korea attributed an attack on Korea Hydro and Nuclear Power to it, and the United States has described it as a unit of the Reconnaissance General Bureau. Springtail initially specialized in South Korean public-sector targets and has used spear-phishing personas posing as journalists, academics, and East Asia specialists. Its campaigns increasingly abuse software supply chains and trojanized installers, including packages for TrustPKI, NX_PRNMAN, and Wizvera VeraPort. The group deploys information stealers and backdoors such as Troll Stealer, GoBear, BetaSeed, and the Linux Gomir backdoor, which support system discovery, command execution, file collection, persistence, proxying, and exfiltration. Its operations emphasize espionage against government-linked organizations and careful compromise of software likely to be installed by intended South Korean victims.

Related Actors

Related Reports in This Cluster

Top Authors

View Springtail reports only

View Springtail reports only