Listen to this Post
A recent investigation by the AhnLab Security Intelligence Center (ASEC) has shed light on a new cyber espionage campaign attributed to North Korea-linked threat actor group Kimsuky. Known for their targeted attacks on government entities, think tanks, and corporate sectors, the group has once again made headlines by exploiting a critical RDP vulnerability to launch a series of sophisticated attacks. This campaign, tracked under the name Larva-24005, offers new insights into Kimsuky’s evolving tactics and the growing threat of state-sponsored cyberattacks.
ASEC’s analysis revealed that Kimsuky successfully infiltrated target systems using a Remote Desktop Protocol (RDP) vulnerability, namely BlueKeep (CVE-2019-0708). In addition to RDP exploitation, the attackers leveraged multiple methods, including phishing emails with malicious attachments and exploiting a critical flaw in the Microsoft Office Equation Editor (CVE-2017-11882). Once inside, the group used advanced malware such as MySpy and RDPWrap to maintain persistent access, while deploying keyloggers like KimaLogger and RandomQuery to capture sensitive data. Since September 2023, Kimsuky has targeted organizations across South Korea, the U.S., China, Japan, Germany, Singapore, and beyond, affecting industries ranging from finance to energy.
This new phase in Kimsuky’s operations shows their adaptability and growing sophistication, with a distinct focus on covert surveillance and cyber espionage. The group’s past exploits, detailed by ASEC and other cybersecurity experts, highlight its ongoing mission to gather intelligence for North Korea’s military and political advantage. In this analysis, we will explore the key findings from ASEC’s report and what these mean for the global cybersecurity landscape.
Key Findings from the Kimsuky Campaign
In their investigation, ASEC researchers traced the Kimsuky group’s movements, documenting the various attack vectors used to gain unauthorized access to critical systems. The group’s first step involved exploiting the BlueKeep vulnerability (CVE-2019-0708), a flaw in Microsoft’s RDP service, which had previously been used in global attacks like the WannaCry ransomware outbreak. However, despite the presence of an RDP vulnerability scanner in the compromised system, ASEC found no concrete evidence that it was used in the attack.
Kimsuky’s campaign was multifaceted, utilizing various methods to spread malware and maintain access. One notable method involved phishing emails, often containing malicious attachments, which were designed to exploit the Microsoft Office Equation Editor vulnerability (CVE-2017-11882). Upon opening the infected file, users unknowingly activated a chain of events that allowed Kimsuky to install malware such as MySpy and RDPWrap. These tools allowed the attackers to maintain remote access, evade detection, and exfiltrate data with minimal risk of being caught.
As the attack progressed, Kimsuky installed keyloggers like KimaLogger and RandomQuery to monitor keystrokes, allowing the attackers to capture sensitive information. In the final stages, the group used phishing campaigns targeting organizations across South Korea and Japan, reflecting their continued focus on specific geopolitical interests.
Additionally, the ASEC report revealed that Kimsuky has been active since 2013, with previous campaigns targeting organizations in South Korea, the U.S., Europe, and Russia. The group is believed to be operating under the Reconnaissance General Bureau (RGB), North Korea’s foreign intelligence service, which is responsible for coordinating such cyber espionage activities.
What Undercode Say:
Kimsuky’s latest cyber espionage campaign serves as a stark reminder of the growing sophistication and frequency of state-sponsored cyberattacks. The group’s ability to exploit both well-known vulnerabilities and newer attack vectors demonstrates their adaptability and persistence. This campaign highlights the persistent risks associated with remote desktop services, particularly RDP, which continues to be a major target for cybercriminals and nation-state actors alike.
The exploitation of vulnerabilities such as BlueKeep and CVE-2017-11882 emphasizes the critical need for organizations to regularly update and patch their systems. Failure to do so opens doors for attackers to gain access and perform potentially catastrophic damage. Furthermore, the use of phishing emails and weaponized documents is an ongoing trend in cybercrime, showcasing how easily attackers can trick users into executing harmful software.
The Kimsuky group’s deployment of sophisticated malware like MySpy, RDPWrap, and keyloggers demonstrates their long-term focus on maintaining remote access, extracting intelligence, and silently monitoring their targets. The use of custom-built RDP Wrap tools highlights their understanding of system administration and their ability to bypass standard detection techniques. These tools are essential for the group’s operations, enabling them to stay hidden while controlling compromised systems.
Notably, Kimsuky’s targets reflect a well-defined geopolitical strategy. The group’s focus on organizations in South Korea, Japan, and the broader East Asian region underscores their intent to gather intelligence for North Korea’s political and military ambitions. The targeting of software, energy, and financial sectors in South Korea, along with attacks on global organizations, suggests that Kimsuky is expanding its reach and capacity to infiltrate critical infrastructure worldwide.
Given the nature of these attacks, organizations must adopt a proactive approach to cybersecurity. This includes not only patching vulnerabilities but also training employees to recognize phishing attempts and deploying advanced security tools like intrusion detection systems and endpoint protection. Additionally, international collaboration and information-sharing among cybersecurity entities will be crucial in combating state-sponsored threats like those posed by Kimsuky.
Fact Checker Results:
- Accuracy of CVE vulnerabilities: The report accurately reflects known CVE-2019-0708 and CVE-2017-11882 vulnerabilities.
– Tactics, techniques, and procedures (TTPs):
- Geopolitical targeting: The emphasis on South Korea, Japan, and related sectors is consistent with past Kimsuky campaigns targeting these regions.
References:
Reported By: securityaffairs.com
Extra Source Hub:
https://www.reddit.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




