North Korean group Kimsuky has launched a sophisticated phishing campaign using HWP documents and concealed AnyDesk backdoors to target victims by pretending to be in academic collaborations. The campaign demonstrates ongoing refinement in spear-phishing tactics and the exploitation of legitimate software for covert remote access. #Kimsuky #AnyDeskBackdoor
Keypoints
- Kimsuky is deploying advanced spear-phishing campaigns with HWP files and stealthy AnyDesk backdoors.
- The attack starts with a phishing email posing as an academic request, containing a password-protected HWP document.
- Malicious files are dropped into the system, triggering scripts that steal information and establish persistent remote access.
- The malware uses legitimate tools like AnyDesk and Dropbox for command and control, avoiding detection.
- The attack chain emphasizes stealth, with hidden interfaces and fileless persistence techniques to maintain access.
Read More: https://securityonline.info/kimsuky-apt-group-abuses-hwp-and-anydesk-for-covert-remote-surveillance/