THE Kimsuky group, associated with North Korea, conducted espionage and credential theft attacks targeting two South Korean groupware vendors between late 2025 and early 2026. They exploited vulnerabilities in a mail server and an employee's PC to deploy Linux backdoors, BirdTroy and DriveTroy. These backdoors allowed the group to steal customer records and access client networks.
The attackers utilized a heavily modified groupware login page for credential harvesting and concealed command-and-control communication via Google Drive. Despite their sophisticated approach, no arrests or legal actions have been taken against them, but the incident highlights the risks vendors pose to customer networks and stresses the need for improved cybersecurity measures.