cognitive cybersecurity intelligence

News and Analysis

Search

Kimsuky shifts tactics from traditional backdoors to RDP, proxies

North Korean hacking group Kimsuky is changing its tactics, using the remote desktop protocol (RDP) and proxy tools rather than traditional backdoors to take over systems. This approach is designed to enhance stealth and maintain persistence. The cyberespionage group delivers its malware through spear-phishing emails containing disguised .LNK shortcut files. The modified version of the RDP Wrapper utility is used to bypass malicious file detection, while proxy tools facilitate access to private networks. Targets are mainly South Korean organizations, but also include the US, Japan, and Germany.

Source: www.scworld.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Infostealers Aimed At MacOS Surges

MacOS-targeted information-stealing malware spiked by 101% in the latter half of 2024, making up most of macOS’s malware that year. Despite their limited capacity, these