Kimsuky targeted a South Korean groupware vendor in an intrusion that researchers linked to a new Gomir malware family variant, adding to evidence of supply-chain-focused activity against software providers. ENKI reported that the campaign involved Linux-targeting, Go-based backdoors and highlighted overlap with HttpTroy-related tradecraft, while social reporting on the incident described the operation as combining phishing and supply-chain elements.
The analysis tied the intrusion to three closely related backdoors—Gomir, BirdTroy, and DriveTroy—that share persistence logic, command structures, and operator behavior. Gomir was described as a Linux variant of GoBear RAT using HTTPS POST communications, custom encoding and encryption, and systemd or cron persistence; BirdTroy reused Gomir persistence code while adding HTTP and HTTP/3 QUIC transport; and DriveTroy used embedded OAuth credentials to exchange host data and task files through Google Drive. ENKI said the report includes C2 infrastructure, malware hashes, embedded credentials, and YARA detection rules for all three families.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
ENKI WhiteHat said Kimsuky targeted South Korean collaborative-work software vendors in 2025 and early 2026, compromising one via a mail-server RCE flaw and another through employee social engineering. The attackers then used those vendor breaches to access customer environments, stole customer server information, tampered with login pages to harvest credentials, and reached at least one SaaS customer.
ENKI published an analysis stating that Kimsuky attacked a South Korean groupware vendor using a new Gomir-family malware variant. The report also described related Linux backdoors including Gomir, BirdTroy, and DriveTroy, and provided infrastructure, hashes, and YARA rules.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcetherecord.media
Open sourcebsky.app
Open sourceenki.co.kr
Open sourcebsky.app
Open sourceenki.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.