South Korean think tanks targeted in Kimsuky spy campaign

Share this article:

A cyber espionage group has targeted several South Korean think tanks, as well as a smaller number of entities in China, to deliver a data-stealing trojan.

According to Dmitry Tarakanov, a Kaspersky researcher who blogged about the threat on Wednesday, this particular campaign is standout due to the fact that the malware's command hub communicates with a Bulgarian email server, and the trojan's authors used Korean hieroglyphs to code the malware.

At least 11 organizations in South Korea were targeted, as well as two in China, Kaspersky found.

The trojan named “Kimsuky” has keylogging capabilities and collects other sensitive data like directory listing information and Word documents on machines. Due to IP addresses and email accounts used in the attacks, researchers believe the group has ties to North Korea.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

More in News

Kevin Mitnick to sell zero-day exploits

Kevin Mitnick's new venture will develop and procure zero-day exploits, then sell them for $100,000 or more.

FBI warns of potential cyber attacks launched by ISIS hacktivists

Following U.S. military airstrikes in the Middle East, the FBI has issued a warning regarding possible cyber threats aimed at U.S. networks and critical infrastructure by hacktivists in support of ISIS.

Report: 75 million records compromised so far in 2014

Report: 75 million records compromised so far in ...

An updated report indicates that since this time last year, breaches have increased by 29.4 percent, with 568 breaches occurring this year.