#apt43
キムスクの新キャンペーンが韓国のソフトウェアベンダーを脅迫

北朝鮮のハッカーが韓国の共同作​​業ソフトウェアベンダーを標的にし、その後、サプライヤーの顧客に侵入することに成功したことが、脅威研究者によって明らかになった。

APT43としても知られるキムスクグループによるこの攻撃は、2025年から2026年初頭にかけて行われた。同グループは過去に、韓国企業の企業インフラや政府機関を標的にしてきた。

韓国のサイバーセキュリティ企業ENKI WhiteHatの研究者が観察した事例の一つでは、ハッカーはリモートコード実行の脆弱性を悪用してマルウェアをインストールすることで、外部からア...
New Kimsuky campaign compromised South Korean software vendors
A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.
therecord.media
August 22, 2026 at 1:10 AM
Kimsuky breached South Korean groupware vendors to reach their SaaS customers - one hack, many victims. https://intel.threadlinqs.com/threat/TL-2026-1643 #ThreatIntel #Gomir #GoBear #Troll
July 23, 2026 at 2:59 AM
北朝鮮系ハッカー集団Kimsuky、韓国のソフトウェアベンダーを標的にした新たな攻撃キャンペーンを展開

北朝鮮のハッカーは、韓国の共同作業用ソフトウェア(グループウェア)ベンダーを標的にし、その後これらサプライヤーの顧客への侵害に成功していたことが、脅威リサーチャーの調査で明らかになりました。  APT43としても知られるKimsuky集団によるこのキャンペーンは、2025年から2026年初頭にかけて実行さ
北朝鮮系ハッカー集団Kimsuky、韓国のソフトウェアベンダーを標的にした新たな攻撃キャンペーンを展開
北朝鮮のハッカーは、韓国の共同作業用ソフトウェア(グループウェア)ベンダーを標的にし、その後これらサプライヤーの顧客への侵害に成功していたことが、脅威リサーチャーの調査で明らかになりました。  APT43としても知られるKimsuky集団によるこのキャンペーンは、2025年から2026年初頭にかけて実行さ
blackhatnews.tokyo
July 22, 2026 at 5:02 PM
APT43 Abuses GitHub and Google Drive to Distribute KimJongRAT: A Deep Dive into the Evolving Threat Landscape + Video

Introduction In May 2026, cybersecurity researchers uncovered a sophisticated attack campaign orchestrated by APT43 (also known as Kimsuky or Earth Kumiho), leveraging legitimate…
APT43 Abuses GitHub and Google Drive to Distribute KimJongRAT: A Deep Dive into the Evolving Threat Landscape + Video
Introduction In May 2026, cybersecurity researchers uncovered a sophisticated attack campaign orchestrated by APT43 (also known as Kimsuky or Earth Kumiho), leveraging legitimate cloud services to distribute the infamous KimJongRAT malware. This campaign represents a significant evolution in the group's tactics, demonstrating an increased reliance on Living Off Trusted Sites (LOTS) techniques, where attackers host malicious components on reputable platforms like GitHub Releases and Google Drive to evade detection and bypass network security controls.
undercodetesting.com
July 10, 2026 at 3:14 AM
Kimsuky (APT43) — Analysis of the New PebbleDash · AppleSeed Toolset dev.to/denniskim/ki...
Kimsuky (APT43) — Analysis of the New PebbleDash · AppleSeed Toolset
CTI-2026-0526-KIMSUKY-PEBBLEDASH Kimsuky (APT43) — Analysis of the New PebbleDash ·...
dev.to
May 26, 2026 at 2:28 PM
Full Article: www.technadu.com/kimsuky-pebb...

What’s your take on the growing abuse of developer platforms and remote management tools in cyberespionage operations? Comment below.
#CyberSecurity #ThreatIntel #Kimsuky #APT43 #Malware #CyberEspionage #VSCode #GitHub #InfoSec
Kimsuky PebbleDash and AppleSeed Malware Campaigns
KimSuky’s PebbleDash and AppleSeed malware campaigns target global defense and South Korean government entities using VSCode and DWAgent.
www.technadu.com
May 15, 2026 at 11:01 AM
Kaspersky researchers linked new PebbleDash tools to Kimsuky’s AppleSeed malware cluster targeting government and defense organizations.
The operation reportedly abused VSCode tunneling, GitHub auth, DWAgent, and Cloudflare Quick Tunnels for persistence.

#CyberSecurity #ThreatIntel #Kimsuky #APT43
May 15, 2026 at 11:01 AM
~Kaspersky~
Kimsuky (APT43) deploys updated PebbleDash malware using VSCode tunneling and a new Rust backdoor (HelloDoor).
-
IOCs: file. bigcloud. n-e. kr, opedromos1. r-e. kr, www. pyrotech. co. kr
-
#Kimsuky #Malware #ThreatIntel
Kimsuky's PebbleDash Campaigns
securelist.com
May 14, 2026 at 12:52 PM
**Kimsuky targets organizations with PebbleDash-based tools**

Over the past few months, we have conducted an in-depth analysis of specific activity clusters of Kimsuky (aka APT43, Ruby Sleet, Black Banshee, Sparkling Pisces, Velvet Chollima, and Springtail), a […]

[Original post on poliverso.org]
May 14, 2026 at 11:51 AM
FBI Flags Kimsuky’s Role in Sophisticated Quishing Attacks #CloudIdentitySecurity #CredentialTheft #CyberAttacks
FBI Flags Kimsuky’s Role in Sophisticated Quishing Attacks
  A new warning from the US Federal Bureau of Investigation indicates that spearphishing tactics are being advanced by a cyber espionage group linked to North Korea known as Kimsuky, also known as APT43, in recent months.  As the threat actor has increasingly turned to QR code-based attacks as a means of infiltrating organizational networks, the threat actor is increasingly using QR code-based attacks.  There is an alert on the group's use of a technique referred to as "quishing," in which carefully crafted spearphishing emails include malicious URLs within QR codes, as opposed to links that are clickable directly in the emails. By using mobile devices to scan the QR codes, recipients can bypass traditional email security gateways that are designed to identify and block suspicious URLs, thereby circumventing the problem.  As a result of this gap between enterprise email defenses and personal mobile use, Kimsuky exploits the resulting gap in security to stealthily harvest user credentials and session tokens, which increases the probability of unauthorized access while reducing the chance of early detection by the security team.  As a result of this campaign, concerns about the increasingly sophisticated sophistication of state-sponsored cyber operations have been reinforced. This is an indication that a broader shift toward more evasive and socially engineered attack methods is taking place.  The FBI has determined Kimsuky has been using this technique actively since at least 2025, with campaigns observing that he targeted think tanks, academic institutions and both US and international government entities using spear phishing emails embedded with malicious Quick Response codes (QR codes).  In describing the method, the bureau referred to it as "quishing," a deliberate strategy based on the notion of pushing victims away from enterprise-managed desktop systems towards networks governed by mobile devices, whose security controls are often more lax or unclear. The Kimsuky attacker, known by various aliases, such as APT43, Black Banshee, Emerald Sleet, Springtail, TA427, Velvet Chollima, and Emerald Sleet, is widely believed to be a North Korean intelligence agency.  Kimsuky's phishing campaigns are documented to have been honed over the years in order to bypass email authentication measures. According to an official US government bulletin published in May 2024, the group has successfully exploited misconfigured Domain-based Message Authentication, Reporting, and Conformance (DMARC) policies to deliver emails that falsely impersonated trusted domains to send emails that convincingly impersonated trusted domains. In this way, they enabled their malicious campaigns to blend seamlessly into legitimate communications, enabling them to achieve their objectives. The attack chain is initiated once a target scans a malicious QR code to initiate the attack chain, that then quickly moves to infrastructure controlled by the threat actors, where preliminary reconnaissance is conducted to understand the victim's device in order to conduct the attack.  Moreover, based on the FBI's findings, these intermediary domains are able to harvest technical information, including operating system details, browser identifiers, screen resolutions, IP addresses, and geographical indications, which allows attackers to tailor follow-up activity with greater precision.  Thereafter, victims are presented with mobile-optimized phishing pages that resemble trusted authentication portals such as Microsoft 365, Okta, and corporate VPN login pages that appear convincingly.  It is believed that by stealing session cookies and executing replay attacks, the operators have been able to circumvent multi-factor authentication controls and seized control of cloud-based identities. Having initially compromised an organization, the group establishes persistence and utilizes the hijacked accounts to launch secondary spear-phishing campaigns. This further extends the intrusion across trust networks by extending the malware laterally.  As described by the FBI, this approach demonstrates a high level of confidence, an identity intrusion vector that is MFA-resilient, and it originates on unmanaged mobile devices that sit outside the traditional lines of endpoint detection and network monitoring.  A number of attacks by Kimsuky were observed during May and June 2025, including campaigns that impersonated foreign advisors, embassy employees, and think tank employees to lure victims into a fictitious conference, as demonstrated by investigators.  Since being active for more than a decade now, North Korea-aligned espionage groups like APT43 and Emerald Sleet have been gathering information on organizations in the United States, Japan, and South Korea. These groups, also known as Velvet Chollima, Emerald Sleet, TA406, and Black Banshee, have traditionally targeted these organizations with information.  As a result of activities related to sanctions evasion and support for Pyongyang's weapons of mass destruction programs in 2023, the U.S. government sanctioned the group. The current spear phishing campaign relies on QR codes embedded within carefully crafted spear-phishing emails to be it's primary infection vector, as the codes run through a victim's mobile device and thereby direct them to an attacker-controlled infrastructure that the attacker controls.  There are a number of websites host phishing pages crafted to look like legitimate authentication portals, like the Microsoft 365, the Google Workspace, Okta and a wide range of services such as VPNs and single sign-ons.  As a general rule, investigators report that the operation typically begins with detailed open-source reconnaissance in order to identify high-value individuals, followed by tailored email messages that impersonate trusted contacts or refer to timely events in order to lend credibility to the operation.  The malicious site either collects login credentials or delivers malware payloads, such as BabyShark or AppleSeed, to the user when they scan the QR code, enabling attackers to establish persistence, move laterally within compromised environments, and exfiltrate sensitive data as soon as it is scanned. There are many MITER ATT&CK techniques that are aligned with the activity, which reflects an organized and methodical tradecraft, which includes credentials harvesting, command-and-control communications at the application layer, and data exfiltration via web services.  Furthermore, the group collects data on victim devices by collecting information about the browser and geolocation of the device, which enables the phishing content to be optimized for mobile use, as well as, in some cases, facilitates session token theft, which allows multi-factor authentication to be bypassed.  Many researchers, academic institutions, government bodies, and strategic advisory organizations have been targeted for their sensitive information, including senior analysts, diplomats, and executives. It has been observed that while the campaign has gained a global presence covering the United States, South Korea, Europe, Russia, and Japan  it has also demonstrated an increased effectiveness because it is based on personalized lures that exploit professional trust networks and QR codes are routinely used for accessing events and sharing documents, which highlights the growing threat of mobile-centric phishing.  In a timely manner, the FBI's advisory serves as a reminder that organizations' attack surfaces are no longer limited to conventional desktops and email gateways, but are increasingly extending into mobile devices which are operating outside of the standard visibility of enterprises.  As malicious actors like Kimsuky develop social engineering techniques that exploit trust, convenience, and routine user behavior in order to gain access to sensitive information, organizations are being forced to reassess how their identity protection strategies intersect with their mobile access policies and their user awareness practices.  There is an urgent need for information security leaders to place greater emphasis on maintaining phishing-resistant authentication, monitoring anomalous sign-in activity continuously, and establishing stronger governance over mobile device usage, including for those employees who are handling sensitive policy, research, or advisory matters.  Additionally, it is imperative that users are educated on how to discern QR codes from suspicious links and attachments so that they can treat QR codes with the same amount of attention and scrutiny.  A combined campaign of this kind illustrates a shift in state-sponsored cyber operations towards low friction, high-impact intrusion paths, which emphasize stealth over scale, pointing to the necessity for adaptive defenses that can evolve as rapidly as the tactics being used to defeat them, which emphasizes the need for a more adaptive defense system.
dlvr.it
January 13, 2026 at 4:47 PM
* ⚠️ APT43 actors using QR codes to bypass email filters
* 🕵️‍♂️ Impersonation of advisors and diplomats is common
* 📲 Attacks focus on harvesting cloud credentials via mobile
* 🏛️ Heavy targeting of U.S. think tanks and academia

👉 Read the article and see our sources: s.vp.net/YHDO1
vp.net
s.vp.net
January 12, 2026 at 9:43 PM
FBI、北朝鮮のハッカーがスピアフィッシングで悪意あるQRコードを使用していると警告

米連邦捜査局(FBI)は木曜日、北朝鮮の国家支援を受けた脅威アクターが、国内の組織を標的とするスピアフィッシング・キャンペーンで悪意あるQRコードを悪用しているとして警告する勧告を公表した。…
FBI、北朝鮮のハッカーがスピアフィッシングで悪意あるQRコードを使用していると警告
米連邦捜査局(FBI)は木曜日、北朝鮮の国家支援を受けた脅威アクターが、国内の組織を標的とするスピアフィッシング・キャンペーンで悪意あるQRコードを悪用しているとして警告する勧告を公表した。 「2025年時点で、Kimsukyのアクターは、スピアフィッシング・キャンペーンに埋め込まれた悪意あるクイックレスポンス(QR)コードを用いて、シンクタンク、学術機関、ならびに米国および外国の政府機関を標的にしてきた」と、FBIはフラッシュアラートで述べた。「この種のスピアフィッシング攻撃は『クイッシング(quishing)』と呼ばれる。」 QRコードを用いたフィッシングは、被害者を企業ポリシーで保護された端末から、同等の保護が提供されない可能性のあるモバイル端末へと移行させる戦術であり、結果として脅威アクターが従来の防御を回避できるようになる。 APT43、Black Banshee、Emerald Sleet、Springtail、TA427、Velvet Chollimaとしても追跡されているKimsukyは、北朝鮮の偵察総局(RGB)に関連していると評価されている脅威グループだ。同グループは、メール認証プロトコルを破ることを特に目的として設計されたスピアフィッシング・キャンペーンを長年にわたり組織してきた。 2024年5月に公開された公報で、米政府は指摘した。このハッキング集団が、設定不備のあるDomain-based Message Authentication, Reporting, and Conformance(DMARC)レコードのポリシーを悪用し、正規のドメインから送信されたように見えるメールを送っていたという。 FBIによると、Kimsukyのアクターが標的型フィッシングの一環として悪意あるQRコードを利用しているのを、2025年5月と6月に複数回観測したという - 朝鮮半島をめぐる最近の動向についてシンクタンクのリーダーから見解を求めるメールで外国人顧問になりすまし、QRコードをスキャンしてアンケートにアクセスするよう促す 北朝鮮の人権問題についてシンクタンクの上級フェローから意見を求めるメールで大使館職員になりすまし、安全なドライブへのアクセスを提供すると称するQRコードを添付する 被害者を、後続の活動のために攻撃者が管理するインフラへ誘導するよう設計されたQRコードを含むメールで、シンクタンク職員になりすます 戦略アドバイザリー企業に対し、存在しない会議への招待メールを送り、受信者にQRコードをスキャンさせて登録用ランディングページへリダイレクトさせる。このページは偽のログインページを用いてGoogleアカウントの認証情報を収集するよう設計されている この公表は、ENKIが、ソウル拠点の物流企業を装ったフィッシングメールで、DocSwapと呼ばれる新たなAndroidマルウェア亜種を配布するためにKimsukyが実施したQRコード・キャンペーンの詳細を明らかにしてから1か月も経たないうちに行われた。 「クイッシング作戦は、セッショントークンの窃取とリプレイで終わることが多く、攻撃者は多要素認証を回避し、典型的な『MFA失敗』アラートを発生させることなくクラウドIDを乗っ取れる」とFBIは述べた。「その後、敵対者は組織内で永続化を確立し、侵害されたメールボックスから二次的なスピアフィッシングを拡散する。」 「侵害経路が、通常のEndpoint Detection and Response(EDR)およびネットワーク検査の境界外にある管理されていないモバイル端末から始まるため、クイッシングは現在、企業環境における高い確度の、MFA耐性を持つID侵害ベクターと見なされている。」 翻訳元:
blackhatnews.tokyo
January 9, 2026 at 6:57 AM
North Korean Kimsuky Hackers Use Malicious QR Codes to Target U.S. Organizations, FBI Warns

The FBI has issued a flash alert warning that the North Korea–backed hacking group Kimsuky (APT43) is using malicious QR codes in spearphishing campaigns to target organizations across the United States.
North Korean Kimsuky Hackers Use Malicious QR Codes to Target U.S. Organizations, FBI Warns
The FBI has issued a flash alert warning that the North Korea–backed hacking group Kimsuky (APT43) is using malicious QR codes in spearphishing campaigns to target organizations across the United States.
www.abijita.com
January 9, 2026 at 1:25 AM
FBI、QRコードを使って米国組織をフィッシングするKimsukyハッカーについて警告

北朝鮮の国家支援ハッカー集団Kimsukyが、米国の組織を標的とするスピアフィッシング・キャンペーンで悪意のある QRコードを使用していると、連邦捜査局(FBI)がフラッシュアラートで警告している。 確認された活動は、北朝鮮関連の政策、研究、分析に関与する組織を標的としており、非政府組織、シンクタンク、学術機関、戦略アドバイザリー企業、米国の政府機関などが含まれる。 フィッシングにQRコードを用いる手口は、「quishing」…
FBI、QRコードを使って米国組織をフィッシングするKimsukyハッカーについて警告
北朝鮮の国家支援ハッカー集団Kimsukyが、米国の組織を標的とするスピアフィッシング・キャンペーンで悪意のある QRコードを使用していると、連邦捜査局(FBI)がフラッシュアラートで警告している。 確認された活動は、北朝鮮関連の政策、研究、分析に関与する組織を標的としており、非政府組織、シンクタンク、学術機関、戦略アドバイザリー企業、米国の政府機関などが含まれる。 フィッシングにQRコードを用いる手口は、「quishing」 としても知られており、新しいものではない。FBIは、サイバー犯罪者がこれを使って金銭を盗んだ際に警告していた が、依然として有効なセキュリティ回避手段である。 Kimsuky(APT43)は、国家支援の北朝鮮系脅威グループ であり、ハッカーがジャーナリストになりすました事例、既知の脆弱性を悪用した事例、サプライチェーン攻撃に依存した事例、そしてClickFix戦術など、複数の攻撃に関連付けられている。 FBIは、昨年のキャンペーンにおいて、Kimsukyに関連するアクターがQRコードを含むメールを送信し、被害者をアンケート、セキュアドライブ、または偽のログインページに偽装した悪意のある場所へリダイレクトさせたと警告している。 同局は、Kimsukyがquishingを用いて標的を攻撃者が管理する場所へ誘導した4つの例を提示した。 被害者をだますため、攻撃者は外国人投資家、大使館職員、シンクタンクのメンバー、会議の主催者を装った。 「2025年6月、Kimsukyのアクターは、存在しない会議への招待を装ったスピアフィッシングメールを戦略アドバイザリー企業に送信した」と、FBIは述べている。 quishing 手法 quishingキャンペーンでは、QRコードをスキャンした被害者は通常、攻撃者が管理するインフラを経由させられ、デバイスのフィンガープリント取得、ユーザーエージェント情報、オペレーティングシステム、IPアドレス、画面サイズ、ローカル言語の収集が行われる。 通常、被害者にはMicrosoft 365、Okta、VPNポータル、またはGoogleのログインページになりすましたフィッシングページが提示され、最終的な目的はアクセス認証情報 またはトークンを盗むことにある。 「quishing作戦は、セッショントークンの窃取とリプレイで終わることが多く、攻撃者は多要素認証を回避し、典型的な『MFA失敗』 アラートを発生させることなくクラウドIDを乗っ取れる」と、同局は指摘している。 標的にモバイル端末でQRコードをスキャンさせるため、脅威アクターは従来のメールセキュリティソリューションを回避でき、侵害された受信箱から悪意のあるメールを配信することも可能になる。 FBIは、これらの攻撃を「MFAに強いID侵入ベクター」 と説明している。これは、標準的なエンドポイント検知・対応(EDR)やネットワーク監視の外にある、管理されていないモバイル端末から発生するためだ。 これらの攻撃に対抗するため、FBIは、対象を絞った従業員トレーニング、QRコードの出所確認、モバイルデバイス管理の導入、多要素認証の徹底を推奨している。 同局は、この種の攻撃の標的となった場合、最寄りのFBIサイバー班またはIC3ポータルに直ちに報告すべきだとしている。 翻訳元:
blackhatnews.tokyo
January 8, 2026 at 11:01 PM
Microsoft、ゼロデイで悪用された Windows LNK 脆弱性を「緩和」

Microsoft は、複数の国家支援型およびサイバー犯罪系ハッカーグループによってゼロデイ攻撃で悪用されていた、高深刻度の Windows LNK 脆弱性を、ひそかに「緩和」しました。 CVE-2025-9491 として追跡されているこのセキュリティ欠陥は、攻撃者が悪意あるコマンドを Windows LNK ファイル内に隠すことを可能にし、マルウェアの展開や、侵害されたデバイス上での永続化に利用されるおそれがあります。ただし、この攻撃が成功するにはユーザーの操作が必要であり、被害者候補をだまして悪意のある…
Microsoft、ゼロデイで悪用された Windows LNK 脆弱性を「緩和」
Microsoft は、複数の国家支援型およびサイバー犯罪系ハッカーグループによってゼロデイ攻撃で悪用されていた、高深刻度の Windows LNK 脆弱性を、ひそかに「緩和」しました。 CVE-2025-9491 として追跡されているこのセキュリティ欠陥は、攻撃者が悪意あるコマンドを Windows LNK ファイル内に隠すことを可能にし、マルウェアの展開や、侵害されたデバイス上での永続化に利用されるおそれがあります。ただし、この攻撃が成功するにはユーザーの操作が必要であり、被害者候補をだまして悪意のある Windows ショートカット(.lnk)ファイルを開かせる手口が用いられます。 脅威アクターは、メールプラットフォームが危険性の高さから .lnk 添付ファイルを一般的にブロックするため、これらのファイルを ZIP などのアーカイブに入れて配布します。 , Evil Corp、Bitter、APT37、APT43(Kimsuky としても知られる)、Mustang Panda、SideWinder、RedHotel、Konni などを含みます。 ​​「Ursnif、Gh0st RAT、Trickbot などの多様なマルウェアペイロードやローダーが、これらのキャンペーンで観測されています。マルウェア・アズ・ア・サービス(MaaS)プラットフォームの存在により、脅威状況はさらに複雑化しています」と、Trend Micro は述べています。 Arctic Wolf Labs も 10 月に、中国の国家支援型ハッカーグループ Mustang Panda が、ハンガリー、ベルギー、その他の欧州諸国の欧州外交官を標的としたゼロデイ攻撃で、この Windows 脆弱性を悪用し、PlugX リモートアクセス型トロイの木馬(RAT)マルウェアを展開していたと報告しました。 ターゲット欄に表示されない悪意ある引数(Trend Micro) Microsoft がひそかに「パッチ」を配布 ​Microsoft は 3 月、BleepingComputer に対し、このゼロデイ欠陥について「対処を検討する」と述べましたが、「即時対応が必要とされる基準は満たしていない」とも説明していました。 また、11 月のアドバイザリでは、ユーザー操作が関与していることと、「この形式は信頼できない」とシステムがすでにユーザーに警告することを理由に、これを脆弱性とは見なしていないと付け加えました。しかし、脅威アクターは Mark of the Web 回避の脆弱性を悪用することで、これらの警告を迂回し、攻撃の成功率を高めることが可能でした。
blackhatnews.tokyo
December 5, 2025 at 3:30 AM
Tech Takes: Quick Takes - APT43 (podcast) | Jisc
November 21, 2025 at 10:48 AM
"Inside The Shellcode Dissecting North Korean Apt43s Advanced Powershell Loader" published by Bloo. #APT43, #DPRK, #CTI https://bloo.io/blog/inside-the-shellcode-dissecting-north-korean-apt43s-advanced-powershell-loader
November 18, 2025 at 11:30 PM
"Inside The Shellcode Dissecting North Korean Apt43s Advanced Powershell Loader" published by Bloo. #APT43, #DPRK, #CTI https://bloo.io/blog/inside-the-shellcode-dissecting-north-korean-apt43s-advanced-powershell-loader
November 18, 2025 at 1:30 PM
"Tracking The Trackers Lessons From The Apt43 Kimsuky Takedown" published by Bloo. #APTDown, #Kimsuky, #DPRK, #CTI https://bloo.io/blog/tracking-the-trackers-lessons-from-the-apt43-kimsuky-takedown
November 17, 2025 at 1:30 PM
北朝鮮のサイバー攻撃でChatGPTが軍事IDの偽造に利用される

北朝鮮のハッカーがOpenAIのChatGPTを悪用し、韓国の防衛関連機関に対するフィッシング攻撃でディープフェイクの軍人IDカードを生成していたことが研究者らによって判明した。

7月の攻撃は、APT43としても知られるキムスキーグループによるものとされており、同グループは情報収集活動を通じて北朝鮮の外交政策と制裁回避を支援したとして、米国とその同盟国から制裁を受けている。

韓国のサイバーセキュリティ企業Geniansによると、ハッカーたちはChatGPTを利用して、韓国政府および軍職員のIDカードのサンプル画像を作...
North Korean operation uses ChatGPT to forge military IDs as part of cyberattack
The hacking group known as Kimsuky used generative AI to create South Korean military IDs used in a phishing campaign against defense-related institutions, researchers said.
therecord.media
September 18, 2025 at 10:45 PM
North Korea’s Kimsuky hackers (APT43) just showed how dangerous AI can be in the wrong hands.
They exploited ChatGPT to forge fake military IDs used in phishing emails against South Korea’s defense sector. The attacks delivered malware for data theft & remote access.

#CyberSecurity #ChatGPT
September 18, 2025 at 8:15 AM
露出した「キム」データダンプで発見されたキムスキーハッカーのプレイブック

リーク者による北朝鮮関連の俳優「キム」に起因する珍しい違反は、キムスキー(APT43)の作戦に関する前例のない洞察を明らかにした。

「キム」ダンプと呼ばれる9GBのデータセットには、アクティブなbashヒストリー、フィッシングドメイン、OCRワークフロー、カスタムステージャー、Linuxルートキットの証拠が含まれています。これは、中国語のツールとインフラストラクチャを活用して韓国と台湾のネットワークをターゲットにするハイブリッドキャンペーンです。

このリークは、政府のPKIシステム、高度なAiTMフィッシング、お…
Kimsuky Hackers’ Playbook Uncovered in Exposed ‘Kim’ Data Dump
A rare breach attributed to a North Korean–affiliated actor named “Kim” by the leakers has unveiled unprecedented insight into Kimsuky (APT43) operations.
gbhackers.com
September 9, 2025 at 3:19 AM