216.73.217.24

Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

· Published 20/07/2026 21:44

Export JSON

Essential information

Published
20/07/2026 21:44
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
birdtroy drivetroy endoor gobear gomir google drive c2 groupware httpspy httptroy kimsuky south korea supply-chain trollstealer
Related entities
21 indicators, 19 observables, 1 intrusion sets (apt), 28 techniques (mitre), 8 malware

Description

Between 2025 and early 2026, the North Korean-linked group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/ family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous operations.

External references