Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant

0
Medium
Published: 07/20/2026 (07/20/2026, 19:44:30 UTC)
Source: AlienVault OTX General

Description

Between 2025 and early 2026, the North Korean-linked Kimsuky group infiltrated South Korean groupware vendors through vulnerability exploitation and spear-phishing. They deployed two new malware variants, BirdTroy and DriveTroy, based on the Gomir/HttpTroy family. BirdTroy uses custom protocols and HTTP/3 (QUIC) for command-and-control communication, while DriveTroy abuses Google Drive as a C2 channel to evade detection. Following initial compromise, Kimsuky conducted aggressive lateral movement, compromising customer groupware servers and tampering with vendor login pages to harvest credentials. The attackers leveraged legitimate tools like DWAgent for remote access and custom proxy tools for lateral movement. Attribution is supported by malware characteristics, infrastructure patterns including default XAMPP certificates, and historical ASN usage consistent with previous Kimsuky operations.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 10:52:31 UTC

Technical Analysis

The Kimsuky threat actor conducted a targeted campaign against South Korean groupware vendors from 2025 to early 2026. They deployed two new malware variants, BirdTroy and DriveTroy, which are evolutions of the Gomir/HttpTroy malware family. BirdTroy communicates using custom protocols and HTTP/3 (QUIC), while DriveTroy abuses Google Drive as a command-and-control channel to evade detection. Initial access was achieved through vulnerability exploitation and spear-phishing. Post-compromise activities included aggressive lateral movement, credential harvesting via tampered login pages, and the use of legitimate tools such as DWAgent for remote access and custom proxy tools for lateral movement. The campaign's attribution to Kimsuky is supported by malware characteristics, infrastructure details including default XAMPP certificates, and ASN usage consistent with prior Kimsuky operations.

Potential Impact

The campaign enabled Kimsuky to infiltrate South Korean groupware vendors and their customers, potentially compromising sensitive communications and credentials. The use of advanced malware variants with stealthy C2 channels and legitimate tools for lateral movement increases the difficulty of detection and remediation. Credential harvesting and tampering with login pages could lead to further unauthorized access and data compromise within affected organizations.

Defensive Guidance

No specific patches or fixes are indicated for this threat. Mitigation should focus on detecting and blocking the described malware behaviors and C2 channels, including monitoring for unusual HTTP/3 (QUIC) traffic and Google Drive abuse. Organizations should also be vigilant against spear-phishing attempts and secure groupware vendor environments to prevent exploitation. Since no official vendor advisory or patch is provided, check vendor communications for updates. Employing endpoint detection and response solutions capable of identifying the use of legitimate remote access tools like DWAgent in suspicious contexts may also help.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant"]
Adversary
Kimsuky
Pulse Id
6a5e7a9e8b20b763327b0d2d
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincommit.hanbiro.o-r.kr
domainnode828765.dwservice.net
domainnode896147.dwservice.net
domainauth.samecloud.o-r.kr
domainglobal.webjine.o-r.kr
domainnode449013.dwservice.net
domainoauth.shacloud.o-r.kr
domainoobe.webjine.o-r.kr
domainwww.ilskdeid.o-r.kr

Url

ValueDescriptionCopy
urlhttps://www.dwservice.net/
urlhttp://auth.samecloud.o-r.kr/index.php
urlhttp://www.ilskdeid.o-r.kr:8000/
urlhttps://auth.samecloud.o-r.kr/index.php
urlhttps://commit.hanbiro.o-r.kr/index.php
urlhttps://global.webjine.o-r.kr/index.php
urlhttps://oauth.shacloud.o-r.kr:8443
urlhttps://oobe.webjine.o-r.kr/index.php

Hash

ValueDescriptionCopy
hash84e9b066bebd49036b7fc71b5f5f8d83
hasha452a860f973c7a43ea804c17e9427d2
hashaa61e76255a6e13313439655bc02bdf5
hashb1c72139f2cdd9419562369fc6ced4fc
hashbf215181b5140522137b3d4f6b73544a
hashc2e37232556357944a04edf1dec3934b
hashca98a51cebdc802d255030b4baa44ca0
hashdff787bce68c7653495f153c0534cb96
hashe6c6fa32da47d9341b778bfa424abb4c
hashe911f8f7c49476806ada37f3ebb7a28a
hash3fb6111490cac9f5c4b34f9fed459f01c10d2314
hashf3ed0bcc692555fea83c6556abaa5dc2b91bcb38
hash01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648
hash073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9

Ip

ValueDescriptionCopy
ip163.245.195.172
ip69.10.50.165

Threat ID: 6a5f49772a4a8d5989f62c46

Added to database: 07/21/2026, 10:27:03 UTC

Last enriched: 08/20/2026, 10:52:31 UTC

Last updated: 09/04/2026, 14:32:45 UTC

Views: 292

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses