Kimsuky APT Group Abuses HWP and AnyDesk for Covert Remote Surveillance

Kimsuky APT Group Abuses HWP and AnyDesk for Covert Remote Surveillance

North Korean group Kimsuky has launched a sophisticated phishing campaign using HWP documents and concealed AnyDesk backdoors to target victims by pretending to be in academic collaborations. The campaign demonstrates ongoing refinement in spear-phishing tactics and the exploitation of legitimate software for covert remote access. #Kimsuky #AnyDeskBackdoor

Keypoints

  • Kimsuky is deploying advanced spear-phishing campaigns with HWP files and stealthy AnyDesk backdoors.
  • The attack starts with a phishing email posing as an academic request, containing a password-protected HWP document.
  • Malicious files are dropped into the system, triggering scripts that steal information and establish persistent remote access.
  • The malware uses legitimate tools like AnyDesk and Dropbox for command and control, avoiding detection.
  • The attack chain emphasizes stealth, with hidden interfaces and fileless persistence techniques to maintain access.

Read More: https://securityonline.info/kimsuky-apt-group-abuses-hwp-and-anydesk-for-covert-remote-surveillance/