Springtail
2024-03-20 • Symantec • New DEEP#GOSU campaign attributed to Springtail A…
Springtail is Symantec’s designation for the North Korean espionage group also known as Kimsuky. The group first drew public attention in 2014 after South Korea attributed an attack on Korea Hydro and Nuclear Power to it, and the United States has described it as a unit of the Reconnaissance General Bureau. Springtail initially specialized in South Korean public-sector targets and has used spear-phishing personas posing as journalists, academics, and East Asia specialists. Its campaigns increasingly abuse software supply chains and trojanized installers, including packages for TrustPKI, NX_PRNMAN, and Wizvera VeraPort. The group deploys information stealers and backdoors such as Troll Stealer, GoBear, BetaSeed, and the Linux Gomir backdoor, which support system discovery, command execution, file collection, persistence, proxying, and exfiltration. Its operations emphasize espionage against government-linked organizations and careful compromise of software likely to be installed by intended South Korean victims.
-
43
Related Actors
-
799
Related Reports