Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

0
Medium
Published: 07/20/2026 (07/20/2026, 19:44:30 UTC)
Source: AlienVault OTX General

Description

Between 2025 and early 2026, the North Korean-linked Kimsuky group targeted South Korean groupware vendors using spear-phishing and exploitation of vulnerabilities. They deployed two new malware variants, BirdTroy and DriveTroy, derived from the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control, while DriveTroy abuses Google Drive as a C2 channel to evade detection. The attackers performed aggressive lateral movement, compromised customer groupware servers, and tampered with vendor login pages to steal credentials. They also used legitimate remote access tools and custom proxies to facilitate their operations. Attribution is supported by malware traits and infrastructure consistent with previous Kimsuky campaigns.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 10:46:24 UTC

Technical Analysis

The Kimsuky threat actor conducted a targeted campaign against South Korean groupware vendors from 2025 to early 2026. They leveraged spear-phishing and exploited vulnerabilities to gain initial access. Two novel malware variants, BirdTroy and DriveTroy, both part of the Gomir/HttpTroy family, were deployed. BirdTroy communicates via custom protocols and HTTP/3 (QUIC), while DriveTroy uses Google Drive as a covert command-and-control channel. Post-compromise, Kimsuky executed extensive lateral movement, compromised customer servers, and altered vendor login pages to harvest credentials. The attackers utilized legitimate tools such as DWAgent for remote access and custom proxy tools to move laterally within networks. Attribution is based on malware characteristics, infrastructure patterns including default XAMPP certificates, and ASN usage matching prior Kimsuky operations.

Potential Impact

The campaign resulted in unauthorized access to South Korean groupware vendors and their customers' servers, credential theft through tampered login pages, and persistent remote access via malware and legitimate tools. The use of advanced evasion techniques like Google Drive-based C2 and HTTP/3 communications complicates detection and response. The compromise of groupware infrastructure could disrupt business communications and lead to further data breaches.

Mitigation Recommendations

No official patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the specific malware variants and their communication channels, including monitoring for unusual HTTP/3 (QUIC) traffic and Google Drive abuse. Organizations should review and harden groupware vendor login pages to prevent credential harvesting. Use of legitimate remote access tools should be monitored for unauthorized use. Since this is a targeted supply-chain style attack, enhanced phishing defenses and vulnerability management are recommended. Patch status is not yet confirmed — check vendor advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant"]
Adversary
Kimsuky
Pulse Id
6a5e7a9e8b20b763327b0d2d
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincommit.hanbiro.o-r.kr
domainnode828765.dwservice.net
domainnode896147.dwservice.net
domainauth.samecloud.o-r.kr
domainglobal.webjine.o-r.kr
domainnode449013.dwservice.net
domainoauth.shacloud.o-r.kr
domainoobe.webjine.o-r.kr
domainwww.ilskdeid.o-r.kr

Url

ValueDescriptionCopy
urlhttps://www.dwservice.net/
urlhttp://auth.samecloud.o-r.kr/index.php
urlhttp://www.ilskdeid.o-r.kr:8000/
urlhttps://auth.samecloud.o-r.kr/index.php
urlhttps://commit.hanbiro.o-r.kr/index.php
urlhttps://global.webjine.o-r.kr/index.php
urlhttps://oauth.shacloud.o-r.kr:8443
urlhttps://oobe.webjine.o-r.kr/index.php

Hash

ValueDescriptionCopy
hash84e9b066bebd49036b7fc71b5f5f8d83
hasha452a860f973c7a43ea804c17e9427d2
hashaa61e76255a6e13313439655bc02bdf5
hashb1c72139f2cdd9419562369fc6ced4fc
hashbf215181b5140522137b3d4f6b73544a
hashc2e37232556357944a04edf1dec3934b
hashca98a51cebdc802d255030b4baa44ca0
hashdff787bce68c7653495f153c0534cb96
hashe6c6fa32da47d9341b778bfa424abb4c
hashe911f8f7c49476806ada37f3ebb7a28a
hash3fb6111490cac9f5c4b34f9fed459f01c10d2314
hashf3ed0bcc692555fea83c6556abaa5dc2b91bcb38
hash01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648
hash073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9

Ip

ValueDescriptionCopy
ip163.245.195.172
ip69.10.50.165

Threat ID: 6a5f49772a4a8d5989f62c46

Added to database: 07/21/2026, 10:27:03 UTC

Last enriched: 07/21/2026, 10:46:24 UTC

Last updated: 07/21/2026, 14:05:31 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses