KIMSUKY , a suspected North Korea-linked threat actor, is conducting spear phishing campaigns targeting policy, diplomatic, and academic organizations in South Korea and Japan. These campaigns involve malicious shortcut files that deploy backdoor scripts to steal sensitive emails and establish covert remote access via legitimate tools like Chrome Remote Desktop and AnyDesk. The attackers also use generative AI to create a custom Chrome extension to monitor Gmail activity.
The ongoing threats demonstrate significant espionage efforts, necessitating audits of scheduled tasks, remote control software, and browser extensions as protective measures against unauthorized access.