Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS Customer

Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises (TL-2026-1643), also tracked as Groupware Supply-Chain Espionage Campaign, is a high-severity supply-chain compromise, first published 2026-07-22. It is attributed to Kimsuky (North Korea) with high confidence, affects Multiple (unnamed South Korean groupware/collaboration-software, maps to 31 MITRE ATT&CK techniques (T1005, T1008, T1021), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-1643

Threat ID
TL-2026-1643
Also known as
Groupware Supply-Chain Espionage Campaign, Gomir Downstream Pivot Campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-07-22
Last reviewed
2026-07-22
Attribution
Kimsuky
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
technology, software vendors, government administration, finance, academia, construction
Target regions
south korea, East Asia
Detection rules
9
Indicators of compromise
17

Malware and tooling in Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises

Malware and tooling: BetaSeed, GoBear - S1197, Gomir - S1198, HttpSpy, KimJongRat, TRANSLATEXT - S1201, Troll Stealer, NX_PRNMAN, WIZVERA VeraPort

North Korean state-sponsored group Kimsuky (APT43/Black Banshee) compromised South Korean groupware/collaboration-software vendors during 2025-early 2026 via mail-server RCE and employee social engineering, then used vendor access to pivot into downstream SaaS customer environments. ENKI WhiteHat discovered new Gomir malware variants deployed on a compromised vendor's customer server, confirming active supply-chain espionage rather than isolated intrusions.

How Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises works

Between 2025 and early 2026, Kimsuky (tracked as APT43, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, TA427, Springtail, Earth Kumiho, and PatheticSlug — MITRE G0094), the North Korean Reconnaissance General Bureau (RGB)-linked intelligence-collection unit, ran a supply-chain espionage operation against South Korean collaborative-work software (groupware) vendors. South Korean incident-response firm ENKI WhiteHat documented at least two distinct initial-access paths into vendor environments: (1) exploitation of a remote code execution vulnerability in an externally-facing mail server, and (2) social engineering of a vendor employee that led to installation of a remote access tool on the employee's workstation. Once inside vendor infrastructure, the operators moved laterally with unusual aggressiveness, tampered with vendor login pages to harvest employee and customer credentials, and abused the absence of multi-factor authentication on exposed services. Critically, the operators stole customer server information from at least one compromised vendor, using it to identify and pivot into the vendor's downstream SaaS customer organizations — the hallmark of a genuine supply-chain compromise rather than a one-off intrusion. On at least one downstream customer server, ENKI WhiteHat recovered new, previously unseen variants of the Gomir backdoor.

Gomir is the Linux port of GoBear, a Go-based Windows backdoor first documented by S2W and Symantec in February-May 2024 as part of a campaign that also distributed the Troll Stealer credential/document-theft tool. GoBear and its predecessor family share function-name strings with BetaSeed, a C++ backdoor previously attributed to Kimsuky, indicating shared source lineage across the group's Windows and Linux tooling. GoBear/Gomir was originally seeded via trojanized installers for legitimate South Korean security software — including NX_PRNMAN (distributed through a construction-industry association website, more than 3,000 infections identified) and WIZVERA VeraPort (a mandatory security-software launcher for South Korean government and banking sites previously abused by the Lazarus Group in 2020) — with both the malware and its droppers signed using a stolen valid code-signing certificate issued to D2Innovation Co., LTD. Gomir itself supports up to 17 operator commands covering file operations, reverse-proxy tunneling, temporary C2 communication suspension, arbitrary shell command execution, and self-termination; it establishes persistence by re-executing itself with an 'install' command-line argument, and beacons via HTTP POST to hardcoded C2 infrastructure (observed: 216.189.159[.]34, path /mir/index.php).

The same actor cluster has continued rapid tooling iteration through 2026, with ENKI WhiteHat separately documenting a JSONPing C2 beaconing technique, spoofed Cisco Webex meeting invitations used as a phishing lure, and a new HttpSpy implant variant, alongside earlier reporting on the TRANSLATEXT malicious Chrome extension (used against South Korean academia to steal credentials, cookies, and browser screenshots) and the KimJongRAT malware family. This groupware supply-chain campaign is consistent with Kimsuky's established TTPs of spearphishing, watering-hole compromise, browser-extension abuse, GPKI/administrative-certificate theft, and code-signing certificate abuse for intelligence collection against South Korean government, academic, and corporate targets, now extended deliberately into the software supply chain to gain scaled access to multiple downstream victims through a single vendor compromise.

MITRE ATT&CK techniques used in TL-2026-1643

Collection

T1005 Data from Local System; T1113 Screen Capture

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1090.001 Internal Proxy

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location

Exfiltration

T1041 Exfiltration Over C2 Channel

Credential Access

T1056.003 Web Portal Capture; T1111 Multi-Factor Authentication Interception; T1552.004 Private Keys; T1555.003 Credentials from Web Browsers

Execution

T1059.003 Windows Command Shell

Persistence

T1078.003 Local Accounts; T1133 External Remote Services; T1505.003 Web Shell

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566.002 Spearphishing Link

credential-access

T1539 Steal Web Session Cookie

defense-impairment

T1553.002 Code Signing

Resource Development

T1583.004 Server; T1587.001 Malware; T1588.003 Code Signing Certificates; T1588.005 Exploits

Reconnaissance

T1591 Gather Victim Org Information; T1594 Search Victim-Owned Websites

Affected products and versions in Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises

  • Multiple (unnamed South Korean groupware/collaboration-software vendors) — Groupware / collaborative-work software platforms
    Vulnerable versions: internet-facing mail server components (unspecified version)
    Fixed in: not publicly disclosed
  • D2Innovation Co., LTD — Code-signing certificate (abused for malware signing)
    Vulnerable versions: certificate compromised/stolen
    Fixed in: revocation status not publicly confirmed
  • WIZVERA — VeraPort security-software launcher
    Vulnerable versions: installer trojanized in related GoBear/Troll Stealer campaign
    Fixed in: not specified
  • NX (construction-industry association distributor) — NX_PRNMAN
    Vulnerable versions: installer trojanized, 3000+ infections in related campaign
    Fixed in: not specified

Remediation for Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises

Patches

  • Apply vendor patches for the exploited mail-server RCE once vendor/CVE identification is confirmed
  • Revoke and reissue any code-signing certificates confirmed compromised (e.g., D2Innovation Co., LTD certificate abused in prior GoBear/Troll Stealer campaigns)

Immediate actions

  • Patch or take offline any internet-facing mail server pending confirmation it is not vulnerable to known RCE issues; restrict administrative interfaces to VPN/allowlisted IPs
  • Enforce MFA on all externally-reachable vendor and customer-facing login portals, especially groupware/collaboration platforms
  • Audit vendor/groupware login pages for tampering (unauthorized JS injection, form-action hijacking) and rotate all credentials submitted through them
  • Block outbound traffic to 216.189.159[.]34 and the /mir/index.php C2 path at perimeter firewalls and proxies
  • Hunt for Gomir/GoBear indicators on Linux and Windows hosts: processes re-executed with an 'install' argument, unexpected outbound HTTP POST beaconing, SOCKS5 proxy child processes

Workarounds

  • Disable or restrict remote administrative access to mail servers until patched
  • Require step-up authentication for any session originating from a vendor support/remote-access tool

Longer-term hardening

  • Implement software supply-chain vetting for third-party groupware/collaboration vendors, including code-signing certificate validation and SBOM review
  • Deploy EDR with behavioral detection on all vendor-supplied server infrastructure and downstream customer integration points
  • Segment vendor remote-access paths from core customer environments; apply least-privilege service accounts for vendor support access
  • Establish a vendor-breach notification and joint incident-response clause in groupware/SaaS vendor contracts

Weaknesses (CWE) in Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises

CWE-287, CWE-306, CWE-494, CWE-798

Timeline of Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises

  • S2W first documents the GoBear Windows backdoor and Troll Stealer, distributed via trojanized NX_PRNMAN and WIZVERA VeraPort installers signed with a stolen D2Innovation Co., LTD certificate.
  • Symantec/Broadcom and multiple outlets disclose Gomir, the Linux variant of GoBear, beaconing via HTTP POST to 216.189.159[.]34/mir/index.php and supporting up to 17 operator commands.
  • Approximate start of the 2025-early 2026 groupware supply-chain campaign window described by ENKI WhiteHat, during which Kimsuky compromises South Korean collaborative-software vendors.
  • One groupware vendor compromised via remote code execution exploit against an internet-facing mail server (approximate, within campaign window).
  • A second groupware vendor compromised via social engineering of an employee, leading to remote access tool deployment on the employee workstation (approximate, within campaign window).
  • Operators move laterally within vendor networks, tamper with login pages to harvest credentials, and exploit missing MFA on exposed services (approximate).
  • Operators steal customer server information from a compromised vendor and use it to identify and access downstream SaaS customer organizations (approximate).
  • The Record publishes the first public report on the groupware supply-chain campaign, attributing it to Kimsuky/APT43.
  • ENKI WhiteHat discovers new, previously unseen Gomir malware variants deployed on a compromised vendor's downstream customer server, confirming active supply-chain espionage.
  • ENKI WhiteHat publishes follow-on research documenting Kimsuky's JSONPing C2 technique, Webex meeting-invite spoofing, and a new HttpSpy implant variant, showing continued active tool development by the same actor cluster.

Sources cited for Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises

More in supply chain

Detection coverage for TL-2026-1643

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1643 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats