the King of the Spear-Phishing
First seen: 2013-09 •
Last seen: 2026-06
#D2Innovation • 2024-01
Kimsuky used trojanized security or software installers masquerading as legitimate Korean software packages, including TrustPKI and NX_PRNMAN, to deploy Troll Stealer/TrollAgent and related backdoor malware. The installers executed normal setup files as decoys while running Go-based, VMProtect-protected malware to collect host information, steal data, and receive external commands, with samples signed using a valid D2innovation Co.,LTD certificate.
6
Related Reports
1
Affected Countries
29
Months Since
the King of the Spear-Phishing