Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

0
Medium
Published: 08/20/2026 (08/20/2026, 17:08:37 UTC)
Source: AlienVault OTX General

Description

Kimsuky conducted spear phishing campaigns targeting South Korean and Japanese entities in early 2026. The attacks used LNK malware distributed via OneDrive share links to establish scheduled tasks that fetched PowerShell scripts for system profiling, email data exfiltration, and keystroke logging. The threat actor abused legitimate remote control tools such as Chrome Remote Desktop and AnyDesk to evade detection and maintain persistent access. A malicious Chrome extension designed to steal Gmail data showed signs of AI-generated code with Korean comments and emojis. The operation used rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to hinder tracking efforts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/20/2026, 23:56:39 UTC

Technical Analysis

This campaign by the threat actor Kimsuky involved spear phishing attacks against targets in Northeast Asia, specifically South Korea and Japan, during the first half of 2026. Attackers distributed LNK malware through OneDrive links, which created scheduled tasks to periodically download PowerShell scripts from command-and-control servers. These scripts performed system profiling, exfiltrated Thunderbird and Outlook email data, and logged keystrokes. To maintain stealth and persistence, Kimsuky installed legitimate remote control software including Chrome Remote Desktop and AnyDesk. Additionally, a malicious Chrome extension aimed at stealing Gmail credentials was deployed, characterized by AI-generated code with Korean-language comments and Unicode emojis. The adversary employed rotating infrastructure and compromised legitimate Korean servers as C2 nodes to complicate detection and tracking.

Potential Impact

The campaign enabled the threat actor to gain persistent remote access to victim systems, evade antivirus detection by using legitimate remote control tools, and exfiltrate sensitive email data from Thunderbird, Outlook, and Gmail accounts. The use of scheduled tasks and PowerShell scripts allowed continuous system profiling and keystroke logging, increasing the risk of credential theft and further compromise. The operation's use of compromised legitimate servers for command-and-control infrastructure complicated incident response and attribution efforts.

Defensive Guidance

No official patches or fixes apply as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear phishing attempts, monitoring for suspicious LNK files and scheduled tasks, and identifying unauthorized installations of remote control software such as Chrome Remote Desktop and AnyDesk. Monitoring network traffic for connections to known command-and-control URLs and hashes provided can aid detection. Removal of the malicious Chrome extension and user education on phishing risks are also recommended.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia"]
Adversary
Kimsuky
Pulse Id
6a873495a873c0ec3c6d9880
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hasheb80f7bddb699784baa9fbf2941eaf4a
hashb9ad79eaf7a4133f95f24c3b9d976c72f34264dc5c99030f0e57992cb5621f78
hashdf6abbfd20e731689f3c7d2a55f45ac83fbbc40b
hasha2191f29f58b9f0cb576b7459ed6680d
hashc08ea73bac08ea4f4665e9e0b0fdd2a8
hashc774b3980151881d9d546710126b5ded
hashcac69a696fc155717dabe641f22db0c9
hashd7dbce5d25aa483d9c5ec1223ed6bf6e
hashe7da02737751f2f171aed28694b9554e
hashe8aaa4f579e6be788929d3548b31bf6d
hashf3620e42e9c726c65ea7e14e3bf35464
hashf6f7a94c11ea0ee01cbbe674cfac7851

Url

ValueDescriptionCopy
urlhttp://103.249.117.183/receive.php
urlhttp://103.77.242.187/receive.php
urlhttp://160.187.147.119/any/app.vmd
urlhttp://160.187.147.119/any/attach.vmd
urlhttp://160.187.147.119/any/bimage.vmd
urlhttp://160.187.147.119/any/mnfst.vmd
urlhttp://160.187.147.119/any/sch.vmd
urlhttp://160.187.147.119/any/vpost.vmd

Threat ID: 6a878fb4acd9273b49493ddc

Added to database: 08/20/2026, 23:37:24 UTC

Last enriched: 08/20/2026, 23:56:39 UTC

Last updated: 08/21/2026, 00:41:46 UTC

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses