Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Essential information
- Published
- 20/07/2026 21:44
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- birdtroy drivetroy endoor gobear gomir google drive c2 groupware httpspy httptroy kimsuky south korea supply-chain trollstealer
- Related entities
- 21 indicators, 19 observables, 1 intrusion sets (apt), 28 techniques (mitre), 8 malware
Description
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.