Wed 22 Jul 2026 / 17:14 ET
Kernel
Security 3 min read

Kimsuky hit South Korean groupware vendors to reach their customers

ENKI WhiteHat says the North Korean-linked APT43 group used vendor access, malware and stolen server data to compromise downstream SaaS customers.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Kimsuky hit South Korean groupware vendors to reach their customers
img: The Record

North Korean-linked hackers broke into South Korean groupware vendors and then used those suppliers as a path into customer systems, according to research from South Korean security firm ENKI WhiteHat.

ENKI attributed the activity to Kimsuky, also tracked as APT43, and said the campaign ran through 2025 and early 2026. The targets were vendors that provide collaborative workplace software, the kind of systems employees use for mail, internal communication and business workflows. That makes a vendor compromise more than a vendor problem: once attackers get inside the supplier, they may inherit useful access to customer infrastructure.

In one incident ENKI examined, the attackers reached a groupware vendor through a mail server that was exposed to the internet. They used a remote code execution vulnerability to place malware on the system, according to the researchers. That is the ugly version of a software bug: the attacker does not just crash the service or read data, but can make the server run code of the attacker’s choosing.

ENKI said another vendor was breached after an employee was socially engineered and remote access tools were installed on that person’s PC. The firm did not identify the vendors or the employee involved. It also did not name the affected customers.

Once inside the vendors, Kimsuky operators deployed Gomir, malware that researchers had previously seen, along with newer variants. ENKI said the attackers moved laterally through the compromised environments and stole customer server information from one vendor. That information was then used to target the vendor’s customers.

The downstream compromise was not theoretical. ENKI said it found Gomir installed on a server belonging to a SaaS customer of one compromised vendor. The researchers also reported that the attackers altered login pages at affected vendors so they could capture employee credentials as workers signed in.

ENKI pointed to missing multifactor authentication as a condition that helped the intrusions succeed. Password theft is less useful when a second factor is enforced; without it, a captured credential can be enough to open the door.

Why Kimsuky keeps showing up

Kimsuky has been tied for years to intelligence collection for Pyongyang. The group has targeted South Korean corporate networks and government-related organizations before, according to ENKI and other security researchers.

The U.S. government sanctioned Kimsuky in 2023, saying the group used spear-phishing against people working at government agencies, research centers, think tanks, universities and media organizations. In 2024, researchers at AhnLab Security Intelligence Center documented a separate Kimsuky campaign aimed at small South Korean businesses using malware.

The ENKI findings add another route to that pattern: compromise the software provider, collect internal and customer data, then use that position to go after the organizations that depend on the provider’s systems. It is a familiar supply-chain move, minus the marketing gloss. The weak points ENKI described were exposed servers, exploitable code, employee manipulation and absent multifactor authentication.

This story draws on original reporting from The Record.

More Security/

view all ↗