cognitive cybersecurity intelligence

News and Analysis

Search

Kimsuky APT exploited BlueKeep RDP flaw in attacks against South Korea and Japan

Kimsuky APT exploited BlueKeep RDP flaw in attacks against South Korea and Japan

North Korea-linked group, Kimsuky, has exploited a flaw in Microsoft’s Remote Desktop Services, according to research by AhnLab SEcurity intelligence Center (ASEC). By gaining initial access to target systems, threat actors installed spyware and manipulated configurations to maintain remote access. Observed since 2023, the group mainly targets South Korean organisations and has impacted various other countries through spear-phishing campaigns and software attacks. In some cases, the Kimsuky group has used the ForceCopy stealer malware to capture keystrokes.

Source: securityaffairs.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts