Logpresso attributes a late-July 2025 campaign to Kimsuky that used compressed archives with sex-offender and tax-notice themes to deliver deceptive Windows shortcut files. When opened, the LNK chain runs mshta.exe to retrieve HTA and log files, shows a d…
« Reports in 2025 »
792 reports
The leaked “APT Down - The North Korea Files” material exposed a Deepin workstation dump and VPS data containing malware source code, attack tools, exfiltrated material, and phishing infrastructure tied by the authors to activity against South Korea. ENKI…
AhnLab tracks Larva-25004 as a Kimsuky-linked operation active since at least August 2023 against South Korean public enterprises, defense industry organizations, research institutes, and at least one job seeker of unknown nationality. The group uses spea…
ENKI’s Korean analysis of the “APT Down - The North Korea Files” leak examines the actor’s VMware workstation and VPS dumps, which contained malware source code, attack tools, stolen data, logs, and phishing infrastructure. The leaked rootkit code matched…
Andrew MacPherson’s LABScon 25 talk examines large-scale cryptocurrency crime affecting decentralized finance, including attacks against browser-based wallet interactions, smart contracts, and crypto applications. The excerpt highlights major attack patte…
The excerpt attributes a phishing email impersonating a Korean National Tax Service electronic document notice about 2024 comprehensive income tax surcharges to Kimsuky. The lure is image-based and hides recipient-specific link data inside Base64-encoded …
Logpresso attributes a July 2025 LNK-based intrusion to North Korea-linked Kimsuky, using decoy archives themed around sex offender notification and tax notice documents. The infection chain launches mshta.exe from a disguised shortcut, retrieves encrypte…
TmaxTibero discovered a compromise of its customer support site only after notification from the Gyeonggi Nambu Provincial Police Agency’s security cyber investigation unit. Attackers reportedly replaced the Tibero 7 installer with a malicious file, creat…
GitLab Threat Intelligence linked infrastructure active since at least May 2025 to North Korean operators distributing BeaverTail and InvisibleFerret variants associated with Contagious Interview and Famous Chollima activity. The campaign used a fake hiri…
A Kimsuky-attributed LNK masquerades as a Samsung Electronics meeting-related PDF and launches hidden PowerShell to decode and run a temporary script. The infection chain downloads a decoy PDF and additional scripts from raw.githubusercontent.com under th…
The excerpt attributes an OFX text-stage script from the “Update Schedule_INVITATION - 250625 UNC Ambassador's Roundtable” archive to Kimsuky activity using a diplomatic-themed lure. The PowerShell collects host profiling data, including the first network…
Genians describes a Kimsuky spear-phishing campaign that impersonated a South Korean defense-related institution and used generative AI-created military employee ID card imagery as a lure. The campaign connects earlier ClickFix activity targeting North Ko…
Genians reports a Kimsuky-attributed spear-phishing campaign that abused ChatGPT-generated deepfake imagery of South Korean military government employee ID cards to make a defense-sector lure appear like an ID issuance review task. The activity is tied to…
Intel 471 reviews the Phrack 72 leak of a threat actor workstation and VPS that Saber and cyb0rg claimed belonged to a Kimsuky/Emerald Sleet-linked operator, exposing about 9 GB of malware, credentials, tooling, browser histories, and backdoor documentati…
AhnLab’s August 2025 domestic APT telemetry shows spearphishing remained the dominant intrusion method in South Korea, with LNK files making up the largest share of observed cases. The excerpt describes LNK payloads that extract embedded CAB archives and …