Kaspersky researchers first identified this activity in September 2013 as an ongoing cyber-espionage campaign against South Korean think tanks and government-linked bodies, including the Sejong Institute, the Korea Institute for Defense Analyses, the Ministry of Unification, and Hyundai Merchant Marine, delivered through spear-phishing and a modular spying toolset that logged keystrokes, harvested files, and communicated with operators via a free Bulgarian webmail account while deliberately evading a Korean antivirus vendor's software. What was initially described as a single operation was later tracked by multiple researchers and government agencies as a persistent, North Korea-linked group active since at least 2012, tasked with global intelligence collection on foreign policy, nuclear issues, and Korean Peninsula security, primarily through spearphishing and watering-hole attacks delivering malware such as BabyShark. Subsequent analysis found targeting had expanded beyond South Korea, Japan, and the United States to include Russia and Europe, hitting COVID-19 vaccine researchers, the UN Security Council, human rights groups, journalists, and South Korean military and defense institutes, using an evolving modular spyware suite, weaponized Word documents, and reused infrastructure across years of continuous operations.
Somesing
#Somesing • 2024-01
🇰🇷 Korea, Republic of
Following a security breach on January 27, 2024, in which approximately 730 million SSX tokens were stolen from the SOMESING Foundation, the team promptly notified exchanges to halt deposits and withdrawals and worked with them to freeze the hacker’s accounts. The attack was later attributed to the North Korean Kimsuky group through digital forensics. Despite these efforts and ongoing cooperation with law enforcement, the Digital Asset eXchange Alliance (DAXA) decided to delist SSX. In response, SOMESING stated the delisting was unjust and announced plans to pursue legal action, including an injunction to suspend the decision.
-
4
Related Reports
-
1
Affected Countries
-
31
Months Since
Related Actors
First seen: 2013-09 •
Last seen: 2026-08