Blog | G5 Cyber Security

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

Kimsuky APT, also known as Thallium, Black Banshee, and Velvet Chollima, is a North Korean threat actor active since 2012. The group conducts cyber espionage operations to target government entities mainly in South Korea. The structure and TTPs used in these recent activities align with what has been reported in KISAs report. They have added the Mobile_detect and Anti_IPs modules from type B to type C (KISA report) in order to be able to detect mobile devices.”]

Source: https://blog.malwarebytes.com/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

Exit mobile version