Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Kimsuky conducted spear phishing campaigns targeting South Korean and Japanese entities in early 2026. The attacks used LNK malware distributed via OneDrive share links to establish scheduled tasks that fetched PowerShell scripts for system profiling, email data exfiltration, and keystroke logging. The threat actor abused legitimate remote control tools such as Chrome Remote Desktop and AnyDesk to evade detection and maintain persistent access. A malicious Chrome extension designed to steal Gmail data showed signs of AI-generated code with Korean comments and emojis. The operation used rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to hinder tracking efforts.
AI Analysis
Technical Summary
This campaign by the threat actor Kimsuky involved spear phishing attacks against targets in Northeast Asia, specifically South Korea and Japan, during the first half of 2026. Attackers distributed LNK malware through OneDrive links, which created scheduled tasks to periodically download PowerShell scripts from command-and-control servers. These scripts performed system profiling, exfiltrated Thunderbird and Outlook email data, and logged keystrokes. To maintain stealth and persistence, Kimsuky installed legitimate remote control software including Chrome Remote Desktop and AnyDesk. Additionally, a malicious Chrome extension aimed at stealing Gmail credentials was deployed, characterized by AI-generated code with Korean-language comments and Unicode emojis. The adversary employed rotating infrastructure and compromised legitimate Korean servers as C2 nodes to complicate detection and tracking.
Potential Impact
The campaign enabled the threat actor to gain persistent remote access to victim systems, evade antivirus detection by using legitimate remote control tools, and exfiltrate sensitive email data from Thunderbird, Outlook, and Gmail accounts. The use of scheduled tasks and PowerShell scripts allowed continuous system profiling and keystroke logging, increasing the risk of credential theft and further compromise. The operation's use of compromised legitimate servers for command-and-control infrastructure complicated incident response and attribution efforts.
Mitigation Recommendations
No official patches or fixes apply as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear phishing attempts, monitoring for suspicious LNK files and scheduled tasks, and identifying unauthorized installations of remote control software such as Chrome Remote Desktop and AnyDesk. Monitoring network traffic for connections to known command-and-control URLs and hashes provided can aid detection. Removal of the malicious Chrome extension and user education on phishing risks are also recommended.
Affected Countries
Japan
Indicators of Compromise
- hash: eb80f7bddb699784baa9fbf2941eaf4a
- hash: b9ad79eaf7a4133f95f24c3b9d976c72f34264dc5c99030f0e57992cb5621f78
- hash: df6abbfd20e731689f3c7d2a55f45ac83fbbc40b
- hash: a2191f29f58b9f0cb576b7459ed6680d
- hash: c08ea73bac08ea4f4665e9e0b0fdd2a8
- hash: c774b3980151881d9d546710126b5ded
- hash: cac69a696fc155717dabe641f22db0c9
- hash: d7dbce5d25aa483d9c5ec1223ed6bf6e
- hash: e7da02737751f2f171aed28694b9554e
- hash: e8aaa4f579e6be788929d3548b31bf6d
- hash: f3620e42e9c726c65ea7e14e3bf35464
- hash: f6f7a94c11ea0ee01cbbe674cfac7851
- url: http://103.249.117.183/receive.php
- url: http://103.77.242.187/receive.php
- url: http://160.187.147.119/any/app.vmd
- url: http://160.187.147.119/any/attach.vmd
- url: http://160.187.147.119/any/bimage.vmd
- url: http://160.187.147.119/any/mnfst.vmd
- url: http://160.187.147.119/any/sch.vmd
- url: http://160.187.147.119/any/vpost.vmd
Inside Kimsuky's Abuse of Legitimate Remote Control Tools Across Northeast Asia
Description
Kimsuky conducted spear phishing campaigns targeting South Korean and Japanese entities in early 2026. The attacks used LNK malware distributed via OneDrive share links to establish scheduled tasks that fetched PowerShell scripts for system profiling, email data exfiltration, and keystroke logging. The threat actor abused legitimate remote control tools such as Chrome Remote Desktop and AnyDesk to evade detection and maintain persistent access. A malicious Chrome extension designed to steal Gmail data showed signs of AI-generated code with Korean comments and emojis. The operation used rotating infrastructure and compromised legitimate Korean servers as command-and-control nodes to hinder tracking efforts.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign by the threat actor Kimsuky involved spear phishing attacks against targets in Northeast Asia, specifically South Korea and Japan, during the first half of 2026. Attackers distributed LNK malware through OneDrive links, which created scheduled tasks to periodically download PowerShell scripts from command-and-control servers. These scripts performed system profiling, exfiltrated Thunderbird and Outlook email data, and logged keystrokes. To maintain stealth and persistence, Kimsuky installed legitimate remote control software including Chrome Remote Desktop and AnyDesk. Additionally, a malicious Chrome extension aimed at stealing Gmail credentials was deployed, characterized by AI-generated code with Korean-language comments and Unicode emojis. The adversary employed rotating infrastructure and compromised legitimate Korean servers as C2 nodes to complicate detection and tracking.
Potential Impact
The campaign enabled the threat actor to gain persistent remote access to victim systems, evade antivirus detection by using legitimate remote control tools, and exfiltrate sensitive email data from Thunderbird, Outlook, and Gmail accounts. The use of scheduled tasks and PowerShell scripts allowed continuous system profiling and keystroke logging, increasing the risk of credential theft and further compromise. The operation's use of compromised legitimate servers for command-and-control infrastructure complicated incident response and attribution efforts.
Defensive Guidance
No official patches or fixes apply as this is a threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear phishing attempts, monitoring for suspicious LNK files and scheduled tasks, and identifying unauthorized installations of remote control software such as Chrome Remote Desktop and AnyDesk. Monitoring network traffic for connections to known command-and-control URLs and hashes provided can aid detection. Removal of the malicious Chrome extension and user education on phishing risks are also recommended.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.enki.co.kr/en/media-center/blog/inside-kimsuky-s-abuse-of-legitimate-remote-control-tools-across-northeast-asia"]
- Adversary
- Kimsuky
- Pulse Id
- 6a873495a873c0ec3c6d9880
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hasheb80f7bddb699784baa9fbf2941eaf4a | — | |
hashb9ad79eaf7a4133f95f24c3b9d976c72f34264dc5c99030f0e57992cb5621f78 | — | |
hashdf6abbfd20e731689f3c7d2a55f45ac83fbbc40b | — | |
hasha2191f29f58b9f0cb576b7459ed6680d | — | |
hashc08ea73bac08ea4f4665e9e0b0fdd2a8 | — | |
hashc774b3980151881d9d546710126b5ded | — | |
hashcac69a696fc155717dabe641f22db0c9 | — | |
hashd7dbce5d25aa483d9c5ec1223ed6bf6e | — | |
hashe7da02737751f2f171aed28694b9554e | — | |
hashe8aaa4f579e6be788929d3548b31bf6d | — | |
hashf3620e42e9c726c65ea7e14e3bf35464 | — | |
hashf6f7a94c11ea0ee01cbbe674cfac7851 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://103.249.117.183/receive.php | — | |
urlhttp://103.77.242.187/receive.php | — | |
urlhttp://160.187.147.119/any/app.vmd | — | |
urlhttp://160.187.147.119/any/attach.vmd | — | |
urlhttp://160.187.147.119/any/bimage.vmd | — | |
urlhttp://160.187.147.119/any/mnfst.vmd | — | |
urlhttp://160.187.147.119/any/sch.vmd | — | |
urlhttp://160.187.147.119/any/vpost.vmd | — |
Threat ID: 6a878fb4acd9273b49493ddc
Added to database: 08/20/2026, 23:37:24 UTC
Last enriched: 08/20/2026, 23:56:39 UTC
Last updated: 08/21/2026, 00:41:46 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.