Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Between 2025 and early 2026, the North Korean-linked Kimsuky group targeted South Korean groupware vendors using spear-phishing and exploitation of vulnerabilities. They deployed two new malware variants, BirdTroy and DriveTroy, derived from the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control, while DriveTroy abuses Google Drive as a C2 channel to evade detection. The attackers performed aggressive lateral movement, compromised customer groupware servers, and tampered with vendor login pages to steal credentials. They also used legitimate remote access tools and custom proxies to facilitate their operations. Attribution is supported by malware traits and infrastructure consistent with previous Kimsuky campaigns.
AI Analysis
Technical Summary
The Kimsuky threat actor conducted a targeted campaign against South Korean groupware vendors from 2025 to early 2026. They leveraged spear-phishing and exploited vulnerabilities to gain initial access. Two novel malware variants, BirdTroy and DriveTroy, both part of the Gomir/HttpTroy family, were deployed. BirdTroy communicates via custom protocols and HTTP/3 (QUIC), while DriveTroy uses Google Drive as a covert command-and-control channel. Post-compromise, Kimsuky executed extensive lateral movement, compromised customer servers, and altered vendor login pages to harvest credentials. The attackers utilized legitimate tools such as DWAgent for remote access and custom proxy tools to move laterally within networks. Attribution is based on malware characteristics, infrastructure patterns including default XAMPP certificates, and ASN usage matching prior Kimsuky operations.
Potential Impact
The campaign resulted in unauthorized access to South Korean groupware vendors and their customers' servers, credential theft through tampered login pages, and persistent remote access via malware and legitimate tools. The use of advanced evasion techniques like Google Drive-based C2 and HTTP/3 communications complicates detection and response. The compromise of groupware infrastructure could disrupt business communications and lead to further data breaches.
Mitigation Recommendations
No official patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the specific malware variants and their communication channels, including monitoring for unusual HTTP/3 (QUIC) traffic and Google Drive abuse. Organizations should review and harden groupware vendor login pages to prevent credential harvesting. Use of legitimate remote access tools should be monitored for unauthorized use. Since this is a targeted supply-chain style attack, enhanced phishing defenses and vulnerability management are recommended. Patch status is not yet confirmed — check vendor advisories for updates.
Indicators of Compromise
- domain: commit.hanbiro.o-r.kr
- url: https://www.dwservice.net/
- domain: node828765.dwservice.net
- domain: node896147.dwservice.net
- hash: 84e9b066bebd49036b7fc71b5f5f8d83
- hash: a452a860f973c7a43ea804c17e9427d2
- hash: aa61e76255a6e13313439655bc02bdf5
- hash: b1c72139f2cdd9419562369fc6ced4fc
- hash: bf215181b5140522137b3d4f6b73544a
- hash: c2e37232556357944a04edf1dec3934b
- hash: ca98a51cebdc802d255030b4baa44ca0
- hash: dff787bce68c7653495f153c0534cb96
- hash: e6c6fa32da47d9341b778bfa424abb4c
- hash: e911f8f7c49476806ada37f3ebb7a28a
- hash: 3fb6111490cac9f5c4b34f9fed459f01c10d2314
- hash: f3ed0bcc692555fea83c6556abaa5dc2b91bcb38
- hash: 01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648
- hash: 073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9
- ip: 163.245.195.172
- ip: 69.10.50.165
- url: http://auth.samecloud.o-r.kr/index.php
- url: http://www.ilskdeid.o-r.kr:8000/
- url: https://auth.samecloud.o-r.kr/index.php
- url: https://commit.hanbiro.o-r.kr/index.php
- url: https://global.webjine.o-r.kr/index.php
- url: https://oauth.shacloud.o-r.kr:8443
- url: https://oobe.webjine.o-r.kr/index.php
- domain: auth.samecloud.o-r.kr
- domain: global.webjine.o-r.kr
- domain: node449013.dwservice.net
- domain: oauth.shacloud.o-r.kr
- domain: oobe.webjine.o-r.kr
- domain: www.ilskdeid.o-r.kr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
Description
Between 2025 and early 2026, the North Korean-linked Kimsuky group targeted South Korean groupware vendors using spear-phishing and exploitation of vulnerabilities. They deployed two new malware variants, BirdTroy and DriveTroy, derived from the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control, while DriveTroy abuses Google Drive as a C2 channel to evade detection. The attackers performed aggressive lateral movement, compromised customer groupware servers, and tampered with vendor login pages to steal credentials. They also used legitimate remote access tools and custom proxies to facilitate their operations. Attribution is supported by malware traits and infrastructure consistent with previous Kimsuky campaigns.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Kimsuky threat actor conducted a targeted campaign against South Korean groupware vendors from 2025 to early 2026. They leveraged spear-phishing and exploited vulnerabilities to gain initial access. Two novel malware variants, BirdTroy and DriveTroy, both part of the Gomir/HttpTroy family, were deployed. BirdTroy communicates via custom protocols and HTTP/3 (QUIC), while DriveTroy uses Google Drive as a covert command-and-control channel. Post-compromise, Kimsuky executed extensive lateral movement, compromised customer servers, and altered vendor login pages to harvest credentials. The attackers utilized legitimate tools such as DWAgent for remote access and custom proxy tools to move laterally within networks. Attribution is based on malware characteristics, infrastructure patterns including default XAMPP certificates, and ASN usage matching prior Kimsuky operations.
Potential Impact
The campaign resulted in unauthorized access to South Korean groupware vendors and their customers' servers, credential theft through tampered login pages, and persistent remote access via malware and legitimate tools. The use of advanced evasion techniques like Google Drive-based C2 and HTTP/3 communications complicates detection and response. The compromise of groupware infrastructure could disrupt business communications and lead to further data breaches.
Mitigation Recommendations
No official patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the specific malware variants and their communication channels, including monitoring for unusual HTTP/3 (QUIC) traffic and Google Drive abuse. Organizations should review and harden groupware vendor login pages to prevent credential harvesting. Use of legitimate remote access tools should be monitored for unauthorized use. Since this is a targeted supply-chain style attack, enhanced phishing defenses and vulnerability management are recommended. Patch status is not yet confirmed — check vendor advisories for updates.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant"]
- Adversary
- Kimsuky
- Pulse Id
- 6a5e7a9e8b20b763327b0d2d
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaincommit.hanbiro.o-r.kr | — | |
domainnode828765.dwservice.net | — | |
domainnode896147.dwservice.net | — | |
domainauth.samecloud.o-r.kr | — | |
domainglobal.webjine.o-r.kr | — | |
domainnode449013.dwservice.net | — | |
domainoauth.shacloud.o-r.kr | — | |
domainoobe.webjine.o-r.kr | — | |
domainwww.ilskdeid.o-r.kr | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://www.dwservice.net/ | — | |
urlhttp://auth.samecloud.o-r.kr/index.php | — | |
urlhttp://www.ilskdeid.o-r.kr:8000/ | — | |
urlhttps://auth.samecloud.o-r.kr/index.php | — | |
urlhttps://commit.hanbiro.o-r.kr/index.php | — | |
urlhttps://global.webjine.o-r.kr/index.php | — | |
urlhttps://oauth.shacloud.o-r.kr:8443 | — | |
urlhttps://oobe.webjine.o-r.kr/index.php | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash84e9b066bebd49036b7fc71b5f5f8d83 | — | |
hasha452a860f973c7a43ea804c17e9427d2 | — | |
hashaa61e76255a6e13313439655bc02bdf5 | — | |
hashb1c72139f2cdd9419562369fc6ced4fc | — | |
hashbf215181b5140522137b3d4f6b73544a | — | |
hashc2e37232556357944a04edf1dec3934b | — | |
hashca98a51cebdc802d255030b4baa44ca0 | — | |
hashdff787bce68c7653495f153c0534cb96 | — | |
hashe6c6fa32da47d9341b778bfa424abb4c | — | |
hashe911f8f7c49476806ada37f3ebb7a28a | — | |
hash3fb6111490cac9f5c4b34f9fed459f01c10d2314 | — | |
hashf3ed0bcc692555fea83c6556abaa5dc2b91bcb38 | — | |
hash01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648 | — | |
hash073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip163.245.195.172 | — | |
ip69.10.50.165 | — |
Threat ID: 6a5f49772a4a8d5989f62c46
Added to database: 07/21/2026, 10:27:03 UTC
Last enriched: 07/21/2026, 10:46:24 UTC
Last updated: 07/21/2026, 14:05:31 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.