South Korean think tanks targeted in Kimsuky spy campaign

Share this article:

A cyber espionage group has targeted several South Korean think tanks, as well as a smaller number of entities in China, to deliver a data-stealing trojan.

According to Dmitry Tarakanov, a Kaspersky researcher who blogged about the threat on Wednesday, this particular campaign is standout due to the fact that the malware's command hub communicates with a Bulgarian email server, and the trojan's authors used Korean hieroglyphs to code the malware.

At least 11 organizations in South Korea were targeted, as well as two in China, Kaspersky found.

The trojan named “Kimsuky” has keylogging capabilities and collects other sensitive data like directory listing information and Word documents on machines. Due to IP addresses and email accounts used in the attacks, researchers believe the group has ties to North Korea.

Share this article:
You must be a registered member of SC Magazine to post a comment.

Sign up to our newsletters

TOP COMMENTS

More in News

Adobe exploit used to spread Dyre credential stealer

Adobe exploit used to spread Dyre credential stealer

Users running vulnerable Adobe software could be in danger of having credentials for Bitcoin websites stolen.

Staples is investigating a potential issue involving credit card data

Staples is investigating a potential issue involving credit ...

The company said it is investigating a potential issue involving credit card data and that customers are not responsible for fraudulent activity on cards if an issue is discovered.

Skills set a priority over legacy prejudices, experts say

Skills set a priority over legacy prejudices, experts ...

Cybersecurity expert Winn Schwartau and Robert Clark, a cyber law attorney at the Army Cyber Institute, discussed issues around hiring in the information security industry.