securityonline.info 8/31/2026, 8:34:22 AM · external

Kimsuky Spear Phishing Abuses Remote Control Tools

Kimsuky Spear Phishing Abuses Remote Control Tools
CyberSIXT Evidence Panel
Primary Source enki.co.kr
Threat Actor

KIMSUKY , a suspected North Korea-linked threat actor, is conducting spear phishing campaigns targeting policy, diplomatic, and academic organizations in South Korea and Japan. These campaigns involve malicious shortcut files that deploy backdoor scripts to steal sensitive emails and establish covert remote access via legitimate tools like Chrome Remote Desktop and AnyDesk. The attackers also use generative AI to create a custom Chrome extension to monitor Gmail activity.

The ongoing threats demonstrate significant espionage efforts, necessitating audits of scheduled tasks, remote control software, and browser extensions as protective measures against unauthorized access.

View Primary Source Via securityonline.info

Article by CyberSIXT