The Korean analysis attributes a large malicious LNK file themed around Hyundai data recovery and procedure establishment to Kimsuky, while noting uncertainty about how the lure content was obtained. The shortcut contains PowerShell that searches for an o…
« Reports in 2025 »
792 reports
AhnLab’s August 2025 APT trend report highlights North Korea-linked campaigns against South Korean policy, media, finance, technology, and diplomatic targets. One Kimsuky case used a journalist impersonation lure against a policy institute, delivering an …
Lazarus Group activity in 2025 combines fake North Korean IT-worker placement, fraudulent recruiting and interview lures, and malicious open-source packages aimed at technology and cryptocurrency organizations. The excerpt links Operation 99/Contagious In…
S2W TALON identified ongoing Kimsuky activity abusing private GitHub repositories to deliver and manage PowerShell malware. The infection begins with a ZIP containing an LNK file disguised as an electronic tax invoice, which launches PowerShell to downloa…
S2W TALON reported Kimsuky activity in which the North Korea-backed group abused private GitHub repositories for malware delivery, script management, and data exfiltration. The attack starts with a ZIP archive containing an LNK file disguised as an electr…
Zscaler ThreatLabz details recent APT37 activity against Windows systems, linking the North Korean-aligned actor to Rustonotto, Chinotto, and FadeStealer. The campaigns use Windows shortcut files and CHM help files as initial delivery vectors, including a…
A Kimsuky-attributed phishing email impersonated South Korea's National Tax Service and Naver electronic document notices to steal Naver account credentials. The lure claimed a September tax filing and payment deadline notice, but the message was sent thr…
DomainTools examines the “Kim” dump as a rare operational leak tied in the text to Kimsuky/APT43 and North Korean-aligned credential theft activity. The material shows South Korean and Taiwanese targeting through phishing domains, AiTM credential capture,…
Chollima Group links the Hailong Jin and Lian Hung personas to suspected North Korean IT worker activity, including GitHub accounts tied to Unity/game development, blockchain work, and overlap with strings seen in Moonstone Sleet's DeTankZone research. Le…
SentinelLABS and Validin observed North Korea-aligned Contagious Interview operators creating and using cyber intelligence platform accounts to monitor their own exposed infrastructure. The activity is tied to the ClickFix-style job seeker lure chain, whe…
GCA's AIDE sensor network observed suspicious activity aligned with Kimsuky operations from January 2023 through August 2025, including a legacy Internet Explorer 11 user-agent previously documented in Kimsuky advisories. The telemetry showed Kimsuky-attr…
NSHC’s August 2025 roundup identifies SectorA activity against finance and cryptocurrency targets using fileless attacks, malicious LNK files, and software package exploitation. The SectorA section highlights the Contagious Interview campaign distributing…
A PowerShell script identified in the source as ESET PowerShell/Kimsuky.AX targeted a South Korean foreign-policy organization and collected host reconnaissance data before staging additional payloads. The script gathered running processes, OS version, pu…
Cyble profiles Lazarus Group as a North Korean state-sponsored actor conducting financially motivated intrusions, espionage, ransomware, supply-chain compromise, and cryptocurrency and fintech targeting alongside broader activity against defense, governme…
FalconFeeds analyzes a leaked Kimsuky operator workstation and related VPS that exposed backdoors, source code, internal documents, browsing history, credentials, and phishing infrastructure. The attribution discussion cites Korean Standard Time configura…