Springtail APT group targets South Korean government entities
2025-04-07 • Symantec •
Springtail, also identified as Kimsuky, targeted South Korean government entities with government-themed malspam using topics such as tax matters and policy around sex offenders. The campaign delivered malicious LNK attachments that downloaded and executed an HTA file to continue the infection chain. Additional payload stages included a ZIP archive containing encoded files, VBS scripts, and PowerShell scripts. The stated objectives included data theft, exfiltration, keylogging, and follow-on malicious activity, making the activity relevant to defenders monitoring DPRK-linked espionage against South Korean public-sector targets.
Related Actors
Related Reports
Shares tag: LNK • Same author: Symantec • Published within a month
Shares tag: Springtail • Same author: Symantec
2024-03-21 •
50% Match
#Springtail
Shares tag: Springtail • Same author: Symantec
2024-03-20 •
50% Match
#Springtail
Shares tag: Springtail • Same author: Symantec
2026-05-14 •
40% Match
#Kimsuky
#Phishing
#AppleSeed
#PebbleDash
#BlackBanshee
#VelvetChollima
#GitHub
#ADS
#APT43
#RubySleet
#Springtail
#HappyDoor
#JSE
#SparklingPisces
#HttpTroy
#VSCode
#T1059.003
#T1005
#T1041
#T1113
#T1071.001
#T1056.001
#T1027
#T1566.001
#T1547.001
#T1053.005
#T1059.001
#T1105
#T1219
#T1543.003
Shares tag: Springtail
Shares tag: LNK • Published within a month