Cybereason uncovers North Korean malware used against companies around the world
Researchers at the cybersecurity firm identified a new spyware suite dubbed KGH_SPY, used by a group with North Korean ties
The victims of the attack are members of the private and public sectors ranging from locations in the United States, Europe, Japan, South Korea, and Russia. Among them are governmental and defense organizations, journalists, human rights groups, and research companies working on coronavirus (Covid-19) remedies.
Kimsuky, also known as Velvet Chollima, Black Banshee, and Thallium, has been active since 2012 and known for complicated infrastructures that use a mixture of free-registered domains, compromised domains, and private domains. Regarding the new KGH_SPY and CSPY Downloader discoveries, Cybereason identified that they are capable of providing the threat actors with reconnaissance, keylogging, and information stealing, all while avoiding detection from anti-virus software.“Our newest discovery shows Kimsuky carrying out targeted cyber espionage campaigns against an array of victims including governments, research institutes and human rights groups,” said Assaf Dahan, Senior Director, Head of Threat Research at Cybereason. “Since the malware is quite new, the true scope of the threat it poses is unknown, but given Kimsuky’s track record this spyware is likely to be of serious concern to both public and private sector organizations.”