ENKI WhiteHat and AhnLab documented the operation. Kimsuky remains sanctioned by the U.S. government since 2023. The threat actor has not filed an appeal. The threat actor will not file an appeal. Audit your groupware vendors and their SaaS environments for unauthorized access and scan for Gomir infections immediately. Reward: You've received a Deprecated Trust Anchor. It does nothing. #APT43 #Kimsuky #SouthKorea #CyberSecurity #Malware #CompromisedAndCounted (2/2)