North Korean Kimsuky Group Leverages Supply Chain Attacks on South Korean Software Vendors
The North Korean state-sponsored hacking group, **Kimsuky** (also known as **APT43**), has orchestrated a sophisticated supply chain attack targeting South Korean collaborative-work software vendors. This campaign, active between 2025 and early 2026, saw the group compromise vendors to subsequently breach their customers, highlighting a persistent and evolving threat landscape.
Threat researchers at the South Korean cybersecurity firm **ENKI WhiteHat** have detailed a series of attacks by the **Kimsuky** group, which successfully infiltrated South Korean groupware vendors before leveraging that access to compromise their downstream customers.
### Initial Breach Tactics
**Kimsuky** employed diverse methods to gain initial access to the vendors. In one instance, they exploited a remote code execution vulnerability on an externally accessible mail server, installing malware to establish a foothold. Another vendor was compromised through social engineering, leading to the deployment of remote access tools on an employee's PC.
### Malware Deployment and Lateral Movement
Upon gaining initial access, the hackers deployed previously identified malware, **Gomir**, alongside new variants. The group demonstrated aggressive lateral movement within the compromised networks, ultimately stealing customer server information from one vendor. This critical data was then used to target the vendor's Software-as-a-Service (SaaS) customers, with **Gomir** being detected on a customer's server.
### Credential Harvesting and MFA Bypass
Further tactics included tampering with the login pages of compromised vendors to harvest employee credentials. **ENKI WhiteHat** researchers noted that the absence of multifactor authentication (MFA) across these systems significantly facilitated the attackers' ability to compromise accounts and expand their access.
### Kimsuky's Persistent Threat
**Kimsuky** is a well-known entity in the threat landscape, recognized for conducting intelligence-gathering campaigns on behalf of Pyongyang. The group was sanctioned by the U.S. government in 2023 for its use of spear-phishing against government, research, academic, and media organizations. Prior campaigns, such as one documented by **AhnLab SEcurity Intelligence Center** in 2024, have targeted small South Korean businesses with various malware strains, underscoring their broad operational scope and adaptability.