Kimsuky was linked to an espionage campaign targeting individuals in South Korea and Japan through phishing emails that delivered OneDrive-hosted archives containing malicious LNK shortcut files. When opened, the shortcut displayed a decoy document while hidden VBE, PowerShell, and batch scripts downloaded follow-on payloads, established persistence with scheduled tasks, collected system information, and stole email data from Thunderbird, Outlook, and Gmail. Researchers also reported in-memory C# keylogging and rapid rotation of command-and-control infrastructure, including the use of compromised Korean servers to complicate tracing.
A key element of the operation was a malicious Chrome extension disguised in Korean as “Gmail automatic server uploader,” which monitored Gmail activity and exfiltrated message metadata, message bodies, and attachments to attacker-controlled servers. The intrusion chain also installed legitimate remote-access tools including Chrome Remote Desktop and AnyDesk for hands-on control, with Chrome Remote Desktop elevated via a fodhelper.exe UAC bypass and AnyDesk maintained through scheduled-task persistence. Enki attributed the activity to Kimsuky based on tooling, targeting, and operational patterns, and assessed that Korean comments, debugging text, and emoji in the extension code strongly suggest generative AI helped produce much of the malware component.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said Enki attributed the campaign to Kimsuky and assessed that generative AI likely helped create much of the malicious Chrome extension's code. The reports also noted Korean comments, debugging text, and emoji in the extension files as supporting evidence.
Enki published a detailed analysis describing the intrusion chain, email theft, keylogging, and abuse of Chrome Remote Desktop and AnyDesk across Northeast Asia. The report said the tradecraft aligned with Kimsuky-style espionage activity.
The campaign deployed a Chrome extension named 'Gmail automatic server uploader' in Korean to monitor Gmail reading and compose activity. It collected sender or recipient details, subjects, message bodies, and attachments, then exfiltrated them to hxxps://sweet-iki-4263.holy[.]jp/gmail.php.
The attackers also installed AnyDesk for remote access and configured it to run in a hidden workflow. A scheduled task named User_Feed_Synchronization-{0DDC1BD9-E733-425C-B92B-ABAC149AB11232} executed the AnyDesk-related script every five minutes, with MyAnyMutexName used to prevent duplicate execution.
The threat actor installed Chrome Remote Desktop to gain GUI-level remote control of victim systems. The setup used fodhelper.exe and the ms-settings protocol handler to bypass UAC and run the installer with elevated privileges.
The attackers ran a PowerShell keylogger that compiled inlined C# code in memory and hooked the keyboard. Captured keystrokes were written to %AppData%\Microsoft\ttmp1.log and likely uploaded later to command-and-control infrastructure.
The campaign used PowerShell scripts to copy local email data from Thunderbird and Outlook mailboxes. Thunderbird messages were parsed from mbox archives and saved as .eml files, while Outlook content and attachments were exported per account.
A separate PowerShell script collected sent and received Outlook messages from local inbox and sent folders. The script specifically harvested messages since January 1, 2026 and stored message data and attachments under C:\users\public\music\mail\.
Follow-on PowerShell scripts collected installed security software and system information from compromised hosts. The data was encoded and sent to attacker infrastructure including 103.77.242[.]187/receive.php.
After execution, a Visual Basic script contacted a command server using the infected device's MAC address and ran a returned PowerShell script in memory. The first-stage malware created a scheduled task named Chrome_Update to persist every 15 minutes.
The campaign used phishing emails containing a OneDrive sharing link to an archive with a malicious Windows shortcut file. When opened, the LNK displayed a decoy document while hidden commands downloaded additional malware.
During the first half of 2026, a phishing-led espionage campaign targeted people in South Korea and Japan. Enki later linked the activity to Kimsuky based on tooling, targeting, and operational patterns.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 45 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceenki.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.