Genians has documented Kimsuky, a North Korean unit under the Reconnaissance General Bureau, building an offline AI stack on its own infrastructure. The group is not training custom models but assembling and testing existing AI tools to automate phishing, malware creation, and data exfiltration.
#Kimsuky #ThreatIntelligence #StateSponsored #AIsecurity
https://cyberworldops.eu/en/kimsuky-prepares-an-offline-ai-stack-to-enhance-phishing-malware-and
#kimsuky
7 posts · Last used Aug 11
Replying to
ENKI WhiteHat and AhnLab documented the operation. Kimsuky remains sanctioned by the U.S. government since 2023. The threat actor has not filed an appeal. The threat actor will not file an appeal.
Audit your groupware vendors and their SaaS environments for unauthorized access and scan for Gomir infections immediately.
Reward: You've received a Deprecated Trust Anchor. It does nothing.
#APT43 #Kimsuky #SouthKorea #CyberSecurity #Malware #CompromisedAndCounted (2/2)
"Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)" published by Ahnlab. #Kimsuky, #Phishing, #PebbleDash, #LNK, #PrxClient https://asec.ahnlab.com/ko/94553/
"Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)" published by Ahnlab. #Kimsuky, #Phishing, #PebbleDash, #LNK, #PrxClient https://asec.ahnlab.com/en/94552/
"신종 Gomir Family를 이용한 Kimsuky의 국내 그룹웨어 개발사 공격 분석" published by ENKI. #Kimsuky, #Phishing, #SupplyChain, #Gomir, #HttpTroy https://www.enki.co.kr/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
"군사·안보 학술지로 위장한 Kimsuky 정찰용 악성코드" published by Hauri. #Kimsuky, #LNK, #GitHub https://hauri.co.kr/security/security_view.html?intSeq=89
You've seen all posts

