Kaspersky researchers first identified this activity in September 2013 as an ongoing cyber-espionage campaign against South Korean think tanks and government-linked bodies, including the Sejong Institute, the Korea Institute for Defense Analyses, the Ministry of Unification, and Hyundai Merchant Marine, delivered through spear-phishing and a modular spying toolset that logged keystrokes, harvested files, and communicated with operators via a free Bulgarian webmail account while deliberately evading a Korean antivirus vendor's software. What was initially described as a single operation was later tracked by multiple researchers and government agencies as a persistent, North Korea-linked group active since at least 2012, tasked with global intelligence collection on foreign policy, nuclear issues, and Korean Peninsula security, primarily through spearphishing and watering-hole attacks delivering malware such as BabyShark. Subsequent analysis found targeting had expanded beyond South Korea, Japan, and the United States to include Russia and Europe, hitting COVID-19 vaccine researchers, the UN Security Council, human rights groups, journalists, and South Korean military and defense institutes, using an evolving modular spyware suite, weaponized Word documents, and reused infrastructure across years of continuous operations.
eScan
#eScan • 2024-04
🇮🇳 India
Avast reported that GuptiMiner hijacked the eScan antivirus update mechanism to distribute backdoors and coinminers, turning trusted security software updates into a supply-chain delivery path. The campaign included a multi-modular backdoor capable of receiving attacker commands, installing additional modules, and scanning local systems for stored private keys and cryptocurrency wallets, with possible Kimsuky ties based on similarities to Kimsuky keylogger components.
-
1
Related Reports
-
1
Affected Countries
-
28
Months Since
Related Actors
First seen: 2013-09 •
Last seen: 2026-08