Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS Customer
Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises (TL-2026-1643), also tracked as Groupware Supply-Chain Espionage Campaign, is a high-severity supply-chain compromise, first published 2026-07-22. It is attributed to Kimsuky (North Korea) with high confidence, affects Multiple (unnamed South Korean groupware/collaboration-software, maps to 31 MITRE ATT&CK techniques (T1005, T1008, T1021), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-1643
- Threat ID
- TL-2026-1643
- Also known as
- Groupware Supply-Chain Espionage Campaign, Gomir Downstream Pivot Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-07-22
- Last reviewed
- 2026-07-22
- Attribution
- Kimsuky
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- technology, software vendors, government administration, finance, academia, construction
- Target regions
- south korea, East Asia
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises
Malware and tooling: BetaSeed, GoBear - S1197, Gomir - S1198, HttpSpy, KimJongRat, TRANSLATEXT - S1201, Troll Stealer, NX_PRNMAN, WIZVERA VeraPort
North Korean state-sponsored group Kimsuky (APT43/Black Banshee) compromised South Korean groupware/collaboration-software vendors during 2025-early 2026 via mail-server RCE and employee social engineering, then used vendor access to pivot into downstream SaaS customer environments. ENKI WhiteHat discovered new Gomir malware variants deployed on a compromised vendor's customer server, confirming active supply-chain espionage rather than isolated intrusions.
How Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises works
Between 2025 and early 2026, Kimsuky (tracked as APT43, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, TA427, Springtail, Earth Kumiho, and PatheticSlug — MITRE G0094), the North Korean Reconnaissance General Bureau (RGB)-linked intelligence-collection unit, ran a supply-chain espionage operation against South Korean collaborative-work software (groupware) vendors. South Korean incident-response firm ENKI WhiteHat documented at least two distinct initial-access paths into vendor environments: (1) exploitation of a remote code execution vulnerability in an externally-facing mail server, and (2) social engineering of a vendor employee that led to installation of a remote access tool on the employee's workstation. Once inside vendor infrastructure, the operators moved laterally with unusual aggressiveness, tampered with vendor login pages to harvest employee and customer credentials, and abused the absence of multi-factor authentication on exposed services. Critically, the operators stole customer server information from at least one compromised vendor, using it to identify and pivot into the vendor's downstream SaaS customer organizations — the hallmark of a genuine supply-chain compromise rather than a one-off intrusion. On at least one downstream customer server, ENKI WhiteHat recovered new, previously unseen variants of the Gomir backdoor.
Gomir is the Linux port of GoBear, a Go-based Windows backdoor first documented by S2W and Symantec in February-May 2024 as part of a campaign that also distributed the Troll Stealer credential/document-theft tool. GoBear and its predecessor family share function-name strings with BetaSeed, a C++ backdoor previously attributed to Kimsuky, indicating shared source lineage across the group's Windows and Linux tooling. GoBear/Gomir was originally seeded via trojanized installers for legitimate South Korean security software — including NX_PRNMAN (distributed through a construction-industry association website, more than 3,000 infections identified) and WIZVERA VeraPort (a mandatory security-software launcher for South Korean government and banking sites previously abused by the Lazarus Group in 2020) — with both the malware and its droppers signed using a stolen valid code-signing certificate issued to D2Innovation Co., LTD. Gomir itself supports up to 17 operator commands covering file operations, reverse-proxy tunneling, temporary C2 communication suspension, arbitrary shell command execution, and self-termination; it establishes persistence by re-executing itself with an 'install' command-line argument, and beacons via HTTP POST to hardcoded C2 infrastructure (observed: 216.189.159[.]34, path /mir/index.php).
The same actor cluster has continued rapid tooling iteration through 2026, with ENKI WhiteHat separately documenting a JSONPing C2 beaconing technique, spoofed Cisco Webex meeting invitations used as a phishing lure, and a new HttpSpy implant variant, alongside earlier reporting on the TRANSLATEXT malicious Chrome extension (used against South Korean academia to steal credentials, cookies, and browser screenshots) and the KimJongRAT malware family. This groupware supply-chain campaign is consistent with Kimsuky's established TTPs of spearphishing, watering-hole compromise, browser-extension abuse, GPKI/administrative-certificate theft, and code-signing certificate abuse for intelligence collection against South Korean government, academic, and corporate targets, now extended deliberately into the software supply chain to gain scaled access to multiple downstream victims through a single vendor compromise.
MITRE ATT&CK techniques used in TL-2026-1643
Collection
T1005 Data from Local System; T1113 Screen Capture
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1090.001 Internal Proxy
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location
Exfiltration
T1041 Exfiltration Over C2 Channel
Credential Access
T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1552.004 Private Keys; T1555.003 Credentials from Web Browsers
Execution
T1059.003 Windows Command Shell
Persistence
T1078.003 Local Accounts; T1133 External Remote Services; T1505.003 Web Shell
Discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.002 Spearphishing Link
credential-access
T1539 Steal Web Session Cookie
defense-impairment
Resource Development
T1583.004 Server; T1587.001 Malware; T1588.003 Code Signing Certificates; T1588.005 Exploits
Reconnaissance
T1591 Gather Victim Org Information; T1594 Search Victim-Owned Websites
Affected products and versions in Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises
- Multiple (unnamed South Korean groupware/collaboration-software vendors) — Groupware / collaborative-work software platforms
Vulnerable versions: internet-facing mail server components (unspecified version)
Fixed in: not publicly disclosed - D2Innovation Co., LTD — Code-signing certificate (abused for malware signing)
Vulnerable versions: certificate compromised/stolen
Fixed in: revocation status not publicly confirmed - WIZVERA — VeraPort security-software launcher
Vulnerable versions: installer trojanized in related GoBear/Troll Stealer campaign
Fixed in: not specified - NX (construction-industry association distributor) — NX_PRNMAN
Vulnerable versions: installer trojanized, 3000+ infections in related campaign
Fixed in: not specified
Remediation for Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises
Patches
- Apply vendor patches for the exploited mail-server RCE once vendor/CVE identification is confirmed
- Revoke and reissue any code-signing certificates confirmed compromised (e.g., D2Innovation Co., LTD certificate abused in prior GoBear/Troll Stealer campaigns)
Immediate actions
- Patch or take offline any internet-facing mail server pending confirmation it is not vulnerable to known RCE issues; restrict administrative interfaces to VPN/allowlisted IPs
- Enforce MFA on all externally-reachable vendor and customer-facing login portals, especially groupware/collaboration platforms
- Audit vendor/groupware login pages for tampering (unauthorized JS injection, form-action hijacking) and rotate all credentials submitted through them
- Block outbound traffic to 216.189.159[.]34 and the /mir/index.php C2 path at perimeter firewalls and proxies
- Hunt for Gomir/GoBear indicators on Linux and Windows hosts: processes re-executed with an 'install' argument, unexpected outbound HTTP POST beaconing, SOCKS5 proxy child processes
Workarounds
- Disable or restrict remote administrative access to mail servers until patched
- Require step-up authentication for any session originating from a vendor support/remote-access tool
Longer-term hardening
- Implement software supply-chain vetting for third-party groupware/collaboration vendors, including code-signing certificate validation and SBOM review
- Deploy EDR with behavioral detection on all vendor-supplied server infrastructure and downstream customer integration points
- Segment vendor remote-access paths from core customer environments; apply least-privilege service accounts for vendor support access
- Establish a vendor-breach notification and joint incident-response clause in groupware/SaaS vendor contracts
Weaknesses (CWE) in Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises
CWE-287, CWE-306, CWE-494, CWE-798
Timeline of Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises
- S2W first documents the GoBear Windows backdoor and Troll Stealer, distributed via trojanized NX_PRNMAN and WIZVERA VeraPort installers signed with a stolen D2Innovation Co., LTD certificate.
- Symantec/Broadcom and multiple outlets disclose Gomir, the Linux variant of GoBear, beaconing via HTTP POST to 216.189.159[.]34/mir/index.php and supporting up to 17 operator commands.
- Approximate start of the 2025-early 2026 groupware supply-chain campaign window described by ENKI WhiteHat, during which Kimsuky compromises South Korean collaborative-software vendors.
- One groupware vendor compromised via remote code execution exploit against an internet-facing mail server (approximate, within campaign window).
- A second groupware vendor compromised via social engineering of an employee, leading to remote access tool deployment on the employee workstation (approximate, within campaign window).
- Operators move laterally within vendor networks, tamper with login pages to harvest credentials, and exploit missing MFA on exposed services (approximate).
- Operators steal customer server information from a compromised vendor and use it to identify and access downstream SaaS customer organizations (approximate).
- The Record publishes the first public report on the groupware supply-chain campaign, attributing it to Kimsuky/APT43.
- ENKI WhiteHat discovers new, previously unseen Gomir malware variants deployed on a compromised vendor's downstream customer server, confirming active supply-chain espionage.
- ENKI WhiteHat publishes follow-on research documenting Kimsuky's JSONPing C2 technique, Webex meeting-invite spoofing, and a new HttpSpy implant variant, showing continued active tool development by the same actor cluster.
Sources cited for Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises
- New Kimsuky campaign compromised South Korean software vendors
- North Korean hackers target South Korean software vendors
- Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
- Kimsuky Distributing Malicious Mobile App via QR Code
- Kimsuky's Ongoing Evolution of KimJongRAT and Expanding Threats
- Linux Backdoor Gomir Detection: North Korean Kimsuky APT aka Springtail Spreads New Malware Variant
- Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks
- Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea
- North Korea-Linked Kimsuky Hackers Use Gomir Backdoor on Linux
- Kimsuky APT Attack Detection: North Korean Hackers Abuse the TRANSLATEXT Chrome Extension to Steal Sensitive Data
- North Korean Advanced Persistent Threat Focus: Kimsuky
- Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug (G0094)
More in supply chain
- Re-Enabled actions-cool GitHub Actions (issues-helper, maintain-one-comment) Resume Executing Mini Shai-Hulud CI/CD Credential-Theft Payload
- Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)
- Adform Ad-Tech Platform Compromised: Trojanized Tracking Script Serves Crypto Clipboard Stealer via Supply-Chain Attack
- DPRK-Linked Graphalgo Campaign Abuses HashiCorp Terraform Registry with Malicious Providers and Go Modules to Deliver Go RAT with Slack and Arbitrum Sepolia Blockchain C2
- GHAPPIER Loader: npm Trusted-Publishing Abuse Compromises @dforge-core/dforge-mcp
Detection coverage for TL-2026-1643
As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1643 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.