#DeepGosu
Incident/Operation
2024-03-18 • Analysis of New DEEP#GOSU Attack Campaign Likely Associated with North Korean Kimsuky Targeting Victims with Stealthy Malware
DEEP#GOSU was a multi-stage malware campaign disclosed in March 2024 and attributed by Symantec to Springtail, also known as Kimsuky or Thallium; Securonix assessed the link to Kimsuky as likely. It targeted South Korean victims through a disguised shortcut delivered in a compressed attachment, then used layered PowerShell and VBScript stagers to retrieve payloads from legitimate cloud platforms. Later stages provided persistence, clipboard monitoring, keylogging, session surveillance, data exfiltration, and remote control. Using Dropbox and Google Docs for command-and-control helped the traffic blend with normal activity and allowed operators to update modules remotely.
-
2
Tagged Reports
-
2
Unique Authors
-
3
Active Days