Springtail APT group targets South Korean government entities

2025-04-07 Symantec

https://www.broadcom.com/support/security-center/protection-bulletin/springtail-apt-group-targets-south-korean-government-entities

Thumbnail for Springtail APT group targets South Korean government entities

Springtail, also identified as Kimsuky, targeted South Korean government entities with government-themed malspam using topics such as tax matters and policy around sex offenders. The campaign delivered malicious LNK attachments that downloaded and executed an HTA file to continue the infection chain. Additional payload stages included a ZIP archive containing encoded files, VBS scripts, and PowerShell scripts. The stated objectives included data theft, exfiltration, keylogging, and follow-on malicious activity, making the activity relevant to defenders monitoring DPRK-linked espionage against South Korean public-sector targets.

Related Actors

Related Reports

« Back