Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
AI Analysis
Technical Summary
The Kimsuky threat actor conducted a targeted campaign against South Korean groupware vendors from 2025 to early 2026. They deployed two new malware variants, BirdTroy and DriveTroy, which are evolutions of the Gomir/HttpTroy malware family. BirdTroy communicates using custom protocols and HTTP/3 (QUIC), while DriveTroy abuses Google Drive as a command-and-control channel to evade detection. Initial access was achieved through vulnerability exploitation and spear-phishing. Post-compromise activities included aggressive lateral movement, credential harvesting via tampered login pages, and the use of legitimate tools such as DWAgent for remote access and custom proxy tools for lateral movement. The campaign's attribution to Kimsuky is supported by malware characteristics, infrastructure details including default XAMPP certificates, and ASN usage consistent with prior Kimsuky operations.
Potential Impact
The campaign enabled Kimsuky to infiltrate South Korean groupware vendors and their customers, potentially compromising sensitive communications and credentials. The use of advanced malware variants with stealthy C2 channels and legitimate tools for lateral movement increases the difficulty of detection and remediation. Credential harvesting and tampering with login pages could lead to further unauthorized access and data compromise within affected organizations.
Mitigation Recommendations
No specific patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the described malware behaviors and C2 channels, including monitoring for unusual HTTP/3 (QUIC) traffic and Google Drive abuse. Organizations should also be vigilant against spear-phishing attempts and secure groupware vendor environments to prevent exploitation. Since no official vendor advisory or patch is provided, check vendor communications for updates. Employing endpoint detection and response solutions capable of identifying the use of legitimate remote access tools like DWAgent in suspicious contexts may also help.
Indicators of Compromise
- domain: commit.hanbiro.o-r.kr
- url: https://www.dwservice.net/
- domain: node828765.dwservice.net
- domain: node896147.dwservice.net
- hash: 84e9b066bebd49036b7fc71b5f5f8d83
- hash: a452a860f973c7a43ea804c17e9427d2
- hash: aa61e76255a6e13313439655bc02bdf5
- hash: b1c72139f2cdd9419562369fc6ced4fc
- hash: bf215181b5140522137b3d4f6b73544a
- hash: c2e37232556357944a04edf1dec3934b
- hash: ca98a51cebdc802d255030b4baa44ca0
- hash: dff787bce68c7653495f153c0534cb96
- hash: e6c6fa32da47d9341b778bfa424abb4c
- hash: e911f8f7c49476806ada37f3ebb7a28a
- hash: 3fb6111490cac9f5c4b34f9fed459f01c10d2314
- hash: f3ed0bcc692555fea83c6556abaa5dc2b91bcb38
- hash: 01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648
- hash: 073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9
- ip: 163.245.195.172
- ip: 69.10.50.165
- url: http://auth.samecloud.o-r.kr/index.php
- url: http://www.ilskdeid.o-r.kr:8000/
- url: https://auth.samecloud.o-r.kr/index.php
- url: https://commit.hanbiro.o-r.kr/index.php
- url: https://global.webjine.o-r.kr/index.php
- url: https://oauth.shacloud.o-r.kr:8443
- url: https://oobe.webjine.o-r.kr/index.php
- domain: auth.samecloud.o-r.kr
- domain: global.webjine.o-r.kr
- domain: node449013.dwservice.net
- domain: oauth.shacloud.o-r.kr
- domain: oobe.webjine.o-r.kr
- domain: www.ilskdeid.o-r.kr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Description
Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kimsuky threat actor conducted a targeted campaign against South Korean groupware vendors from 2025 to early 2026. They deployed two new malware variants, BirdTroy and DriveTroy, which are evolutions of the Gomir/HttpTroy malware family. BirdTroy communicates using custom protocols and HTTP/3 (QUIC), while DriveTroy abuses Google Drive as a command-and-control channel to evade detection. Initial access was achieved through vulnerability exploitation and spear-phishing. Post-compromise activities included aggressive lateral movement, credential harvesting via tampered login pages, and the use of legitimate tools such as DWAgent for remote access and custom proxy tools for lateral movement. The campaign's attribution to Kimsuky is supported by malware characteristics, infrastructure details including default XAMPP certificates, and ASN usage consistent with prior Kimsuky operations.
Potential Impact
The campaign enabled Kimsuky to infiltrate South Korean groupware vendors and their customers, potentially compromising sensitive communications and credentials. The use of advanced malware variants with stealthy C2 channels and legitimate tools for lateral movement increases the difficulty of detection and remediation. Credential harvesting and tampering with login pages could lead to further unauthorized access and data compromise within affected organizations.
Defensive Guidance
No specific patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the described malware behaviors and C2 channels, including monitoring for unusual HTTP/3 (QUIC) traffic and Google Drive abuse. Organizations should also be vigilant against spear-phishing attempts and secure groupware vendor environments to prevent exploitation. Since no official vendor advisory or patch is provided, check vendor communications for updates. Employing endpoint detection and response solutions capable of identifying the use of legitimate remote access tools like DWAgent in suspicious contexts may also help.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant"]
- Adversary
- Kimsuky
- Pulse Id
- 6a5e7a9e8b20b763327b0d2d
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincommit.hanbiro.o-r.kr | — | |
domainnode828765.dwservice.net | — | |
domainnode896147.dwservice.net | — | |
domainauth.samecloud.o-r.kr | — | |
domainglobal.webjine.o-r.kr | — | |
domainnode449013.dwservice.net | — | |
domainoauth.shacloud.o-r.kr | — | |
domainoobe.webjine.o-r.kr | — | |
domainwww.ilskdeid.o-r.kr | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://www.dwservice.net/ | — | |
urlhttp://auth.samecloud.o-r.kr/index.php | — | |
urlhttp://www.ilskdeid.o-r.kr:8000/ | — | |
urlhttps://auth.samecloud.o-r.kr/index.php | — | |
urlhttps://commit.hanbiro.o-r.kr/index.php | — | |
urlhttps://global.webjine.o-r.kr/index.php | — | |
urlhttps://oauth.shacloud.o-r.kr:8443 | — | |
urlhttps://oobe.webjine.o-r.kr/index.php | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash84e9b066bebd49036b7fc71b5f5f8d83 | — | |
hasha452a860f973c7a43ea804c17e9427d2 | — | |
hashaa61e76255a6e13313439655bc02bdf5 | — | |
hashb1c72139f2cdd9419562369fc6ced4fc | — | |
hashbf215181b5140522137b3d4f6b73544a | — | |
hashc2e37232556357944a04edf1dec3934b | — | |
hashca98a51cebdc802d255030b4baa44ca0 | — | |
hashdff787bce68c7653495f153c0534cb96 | — | |
hashe6c6fa32da47d9341b778bfa424abb4c | — | |
hashe911f8f7c49476806ada37f3ebb7a28a | — | |
hash3fb6111490cac9f5c4b34f9fed459f01c10d2314 | — | |
hashf3ed0bcc692555fea83c6556abaa5dc2b91bcb38 | — | |
hash01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648 | — | |
hash073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip163.245.195.172 | — | |
ip69.10.50.165 | — |
Threat ID: 6a5f49772a4a8d5989f62c46
Added to database: 07/21/2026, 10:27:03 UTC
Last enriched: 08/20/2026, 10:52:31 UTC
Last updated: 09/04/2026, 14:32:45 UTC
Views: 292
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.