Skip to main content

Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia

0
Medium
Published: 08/20/2026 (08/20/2026, 17:08:37 UTC)
Source: AlienVault OTX General

Description

Kimsuky conducted spear phishing campaigns targeting South Korean and Japanese entities in early 2026. The attacks used LNK malware distributed via OneDrive share links to establish scheduled tasks that periodically retrieved PowerShell scripts from command-and-control servers. These scripts profiled infected systems, exfiltrated email data from Thunderbird and Outlook, and logged keystrokes. The threat actor leveraged legitimate remote control tools such as Chrome Remote Desktop and AnyDesk to evade antivirus detection and maintain persistent access. Additionally, a malicious Chrome extension with AI-generated code was used to steal Gmail data. The operation employed rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to hinder tracking efforts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 03:33:24 UTC

Technical Analysis

Kimsuky executed spear phishing campaigns in Northeast Asia, specifically targeting South Korean and Japanese organizations. The initial infection vector involved LNK malware distributed through OneDrive share links. Once executed, the malware created scheduled tasks that periodically downloaded PowerShell scripts from attacker-controlled servers. These scripts conducted system profiling, exfiltrated email data from Thunderbird and Outlook clients, and captured keystrokes. To maintain stealth and persistence, Kimsuky installed legitimate remote control software including Chrome Remote Desktop and AnyDesk. A malicious Chrome extension designed to steal Gmail credentials was also deployed, notable for AI-generated code with Korean comments and debug strings. The threat actor used rotating infrastructure and hijacked legitimate Korean servers as command-and-control nodes to complicate detection and attribution.

Potential Impact

The campaign enabled Kimsuky to gain persistent remote access to targeted systems, steal sensitive email communications from Thunderbird, Outlook, and Gmail, and capture user keystrokes. Use of legitimate remote control tools helped evade antivirus detection, increasing the likelihood of prolonged unauthorized access. The compromise of legitimate Korean servers as command-and-control infrastructure further complicated defensive efforts. The overall impact includes data exfiltration, espionage, and potential long-term system compromise in targeted organizations.

Defensive Guidance

No specific patch or fix applies as this is a threat actor campaign rather than a software vulnerability. Organizations should focus on user awareness to prevent spear phishing, monitor for suspicious scheduled tasks and PowerShell activity, and detect unauthorized installation of remote control software. Monitoring for anomalous Chrome extension installations and network connections to known malicious infrastructure may help identify infections. Since legitimate tools are abused, behavioral detection and anomaly-based monitoring are recommended. There is no indication that the threat is mitigated or neutralized by vendor action.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia"]
Adversary
Kimsuky
Pulse Id
6a873495a873c0ec3c6d9880

Indicators of Compromise

Hash

ValueDescriptionCopy
hasheb80f7bddb699784baa9fbf2941eaf4a
—
hashb9ad79eaf7a4133f95f24c3b9d976c72f34264dc5c99030f0e57992cb5621f78
—
hashdf6abbfd20e731689f3c7d2a55f45ac83fbbc40b
—
hasha2191f29f58b9f0cb576b7459ed6680d
—
hashc08ea73bac08ea4f4665e9e0b0fdd2a8
—
hashc774b3980151881d9d546710126b5ded
—
hashcac69a696fc155717dabe641f22db0c9
—
hashd7dbce5d25aa483d9c5ec1223ed6bf6e
—
hashe7da02737751f2f171aed28694b9554e
—
hashe8aaa4f579e6be788929d3548b31bf6d
—
hashf3620e42e9c726c65ea7e14e3bf35464
—
hashf6f7a94c11ea0ee01cbbe674cfac7851
—

Url

ValueDescriptionCopy
urlhttp://103.249.117.183/receive.php
—
urlhttp://103.77.242.187/receive.php
—
urlhttp://160.187.147.119/any/app.vmd
—
urlhttp://160.187.147.119/any/attach.vmd
—
urlhttp://160.187.147.119/any/bimage.vmd
—
urlhttp://160.187.147.119/any/mnfst.vmd
—
urlhttp://160.187.147.119/any/sch.vmd
—
urlhttp://160.187.147.119/any/vpost.vmd
—

Threat ID: 6a878fb4acd9273b49493ddc

Added to database: 08/20/2026, 23:37:24 UTC

Last enriched: 09/11/2026, 03:33:24 UTC

Last updated: 10/03/2026, 17:22:56 UTC

Views: 221

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses