South Korean think tanks targeted in Kimsuky spy campaign

Share this article:

A cyber espionage group has targeted several South Korean think tanks, as well as a smaller number of entities in China, to deliver a data-stealing trojan.

According to Dmitry Tarakanov, a Kaspersky researcher who blogged about the threat on Wednesday, this particular campaign is standout due to the fact that the malware's command hub communicates with a Bulgarian email server, and the trojan's authors used Korean hieroglyphs to code the malware.

At least 11 organizations in South Korea were targeted, as well as two in China, Kaspersky found.

The trojan named “Kimsuky” has keylogging capabilities and collects other sensitive data like directory listing information and Word documents on machines. Due to IP addresses and email accounts used in the attacks, researchers believe the group has ties to North Korea.

Share this article:

Sign up to our newsletters

More in News

'Backoff' malware compromises POS devices in New Orleans restaurant

Anyone that used a credit or debit card at Mizado Cocina between May 9 and July 18 may have had their data compromised.

FBI begins investigation into 1.2 billion stolen credentials

A couple weeks after Hold Security's initial discovery of the stolen logins, the Federal Bureau of Investigation is conducting its own review.

CryptoLocker copycat, TorrentLocker, discovered by researchers

Yet another clone of the nefarious ransomware CryptoLocker has been detected by security experts.