Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

North Korean hackers target South Korean software vendors

The North Korean APT group Kimsuky (APT43) compromised South Korean software vendors in 2025-2026 by exploiting a remote code execution vulnerability on an external mail server and using social engineering to deploy remote access tools. After initial access, they deployed Gomir malware, moved laterally to steal customer data from vendors, and harvested credentials by tampering with login pages, with a lack of multi-factor authentication contributing to the compromises. The attackers then used the stolen information to target the vendors' downstream customers.
Read Full Article →

Threat Intelligence North Korean hackers target South Korean software vendors July 22, 2026 Share By SC Staff (Adobe Stock) North Korean hackers successfully targeted South Korean collaborative-work software vendors before breaching the suppliers’ customers, threat researchers at ENKI WhiteHat have found. The campaign by the Kimsuky group, also known as APT43, was carried out in 2025 and early 2026, with further coverage provided by The Record. The Kimsuky group compromised a groupware vendor through an externally accessible mail server by exploiting a remote code execution vulnerability. Another vendor was compromised through social engineering of an employee, leading to the deployment of remote access tools. After gaining initial access, the hackers deployed known malware called Gomir and new variants. They moved laterally to steal customer server information from a vendor to target its customers. Researchers detected Gomir installed on a server belonging to one of the compromised vendor’s SaaS customers. The hackers also tampered with login pages, harvesting employee credentials, with the lack of multifactor authentication contributing to the compromises. Kimsuky is known for intelligence gathering campaigns on behalf of Pyongyang and was sanctioned by the U.S. government in 2023 for using spear-phishing tactics. Source: The Record SC Staff Related Threat Intelligence North Korea’s IT worker scheme funds Russia’s war effort, report finds SC Staff July 21, 2026 Security firm DTEX's research reveals that the illicit IT worker scheme is a significant revenue stream for North Korea, with funds being channeled through organizations like Sobaeksu, Saenal, and Songkwang. Threat Intelligence Ostium trading platform loses $23.75 million in off-chain exploit SC Staff July 21, 2026 The attacker manipulated illegitimate price reports to disguise them as valid ones, then rapidly opened and closed large positions to generate artificial profits. Threat Intelligence Sophisticated crypter service Cruciferra evades detection with advanced techniques SC Staff July 21, 2026 Cruciferra, first offered for sale in autumn 2025, underpins dozens of campaigns delivering malware such as AsyncRAT, Agent Tesla, and Remcos. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting DNS Spoofing Deauthentication Attack Defacement Dictionary Attack Distributed Scans DumpSec Google Hacking Hybrid Attack Password Cracking You can skip this ad in 5 seconds

Share this article