the King of the Spear-Phishing
First seen: 2013-09 •
Last seen: 2026-06
#asungsoft • 2024-03
Kimsuky distributed malware disguised as installation files for South Korean public institutions, using a dropper signed with a valid domestic company certificate to unpack and execute the Endoor backdoor. The linked evidence connects the activity to Kimsuky tooling including Endoor and Nikidoor, with capabilities to collect infected-system information, receive attacker commands, download additional malware, and capture screenshots.
2
Related Reports
1
Affected Countries
27
Months Since
the King of the Spear-Phishing