Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS Customer — Threadlinqs Intelligence
As of 2026-07-22, Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS Customer is a high-severity supply chain threat attributed to Kimsuky (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1643 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: Kimsuky · North Korea · ESPIONAGE
North Korean state-sponsored group Kimsuky (APT43/Black Banshee) compromised South Korean groupware/collaboration-software vendors during 2025-early 2026 via mail-server RCE and employee social
Between 2025 and early 2026, Kimsuky (tracked as APT43, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, TA427, Springtail, Earth Kumiho, and PatheticSlug — MITRE G0094), the North Korean Reconnaissance General Bureau (RGB)-linked intelligence-collection unit, ran a supply-chain espionage operation against South Korean collaborative-work software (groupware) vendors. South Korean incident-response firm ENKI WhiteHat documented at least two distinct initial-access paths into vendor environments: (1) exploitation of a remote code execution vulnerability in an externally-facing mail server, and (2) social engineering of a vendor employee that led to installation of a remote access tool on the employee's workstation. Once inside vendor infrastructure, the operators moved laterally with unusual aggressiveness, tampered with vendor login pages to harvest employee and customer credentials, and abused the absence of multi-factor authentication on exposed services. Critically, the operators stole customer server information from at least one compromised vendor, using it to identify and pivot into the vendor's downstream SaaS customer organizations — the hallmark of a genuine supply-chain compromise rather than a one-off intrusion. On at least one downstream customer server, ENKI WhiteHat recovered new, previously unseen variants of the Gomir backdoor.
Gomir is the Linux port of GoBear, a Go-based Windows backdoor first documented by S2W and Symantec in February-May 2024 as part of a campaign that also distributed the Troll Stealer credential/document-theft tool. GoBear and its predecessor family share function-name strings with BetaSeed, a C++ backdoor previously attributed to Kimsuky, indicating shared source lineage across the group's Windows and Linux tooling. GoBear/Gomir was originally seeded via trojanized installers for legitimate South Korean security software — including NX_PRNMAN (distributed through a construction-industry association website, more than 3,000 infections identified) and WIZVERA VeraPort (a mandatory security-software launcher for South Korean government and banking sites previously abused by the Lazarus Group in 2020) — with both the malware and its droppers signed using a stolen valid code-signing certificate issued to D2Innovation Co., LTD. Gomir itself supports up to 17 operator commands covering file operations, reverse-proxy tunneling, temporary C2 communication suspension, arbitrary shell command execution, and self-termination; it establishes persistence by re-executing itself with an 'install' command-line argument, and beacons via HTTP POST to hardcoded C2 infrastructure (observed: 216.189.159[.]34, path /mir/index.php).
The same actor cluster has continued rapid tooling iteration through 2026, with ENKI WhiteHat separately documenting a JSONPing C2 beaconing technique, spoofed Cisco Webex meeting invitations used as a phishing lure, and a new HttpSpy implant variant, alongside earlier reporting on the TRANSLATEXT malicious Chrome extension (used against South Korean academia to steal credentials, cookies, and browser screenshots) and the KimJongRAT malware family. This groupware supply-chain campaign is consistent with Kimsuky's established TTPs of spearphishing, watering-hole compromise, browser-extension abuse, GPKI/administrative-certificate theft, and code-signing certificate abuse for intelligence collection against South Korean government, academic, and corporate targets, now extended deliberately into the software supply chain to gain scaled access to multiple downstream victims through a single vendor compromise.
Weaknesses (CWE)
CWE-287, CWE-306, CWE-494, CWE-798
Target sectors: technology, software vendors, government administration, finance, academia, construction
Target regions: south korea, East Asia
References
- New Kimsuky campaign compromised South Korean software vendors
- North Korean hackers target South Korean software vendors
- Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
- Kimsuky Distributing Malicious Mobile App via QR Code
- Kimsuky's Ongoing Evolution of KimJongRAT and Expanding Threats
- Linux Backdoor Gomir Detection: North Korean Kimsuky APT aka Springtail Spreads New Malware Variant
- Kimsuky APT Deploying Linux Backdoor Gomir in South Korean Cyber Attacks
- Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea
- North Korea-Linked Kimsuky Hackers Use Gomir Backdoor on Linux
- Kimsuky APT Attack Detection: North Korean Hackers Abuse the TRANSLATEXT Chrome Extension to Steal Sensitive Data
- North Korean Advanced Persistent Threat Focus: Kimsuky
- Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug (G0094)
Detections & IOCs
As of 2026-07-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1591, T1594, T1588.003, T1588.005, T1587.001, T1583.004, T1190, T1566.002, T1199, T1133