South Korean think tanks targeted in Kimsuky spy campaign

Share this article:

A cyber espionage group has targeted several South Korean think tanks, as well as a smaller number of entities in China, to deliver a data-stealing trojan.

According to Dmitry Tarakanov, a Kaspersky researcher who blogged about the threat on Wednesday, this particular campaign is standout due to the fact that the malware's command hub communicates with a Bulgarian email server, and the trojan's authors used Korean hieroglyphs to code the malware.

At least 11 organizations in South Korea were targeted, as well as two in China, Kaspersky found.

The trojan named “Kimsuky” has keylogging capabilities and collects other sensitive data like directory listing information and Word documents on machines. Due to IP addresses and email accounts used in the attacks, researchers believe the group has ties to North Korea.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

ISSA tackles workforce gap with career lifecycle program

ISSA tackles workforce gap with career lifecycle program ...

On Thursday, the group launched its Cybersecurity Career Lifecycle (CSCL) program.

Amplification DDoS attacks most popular, according to Symantec

Amplification DDoS attacks most popular, according to Symantec

The company noted in a whitepaper released on Tuesday that Domain Name Server amplification attacks have increased 183 percent between January and August.

Court shutters NY co. selling security software with "no value"

A federal court shut down Pairsys at the request of the Federal Trade Commission.