Kimsuky breaches South Korean groupware vendors, then customers
The operational problem is the old one: vendor access became customer access before defenders could treat the supplier as patient zero.
TL;DR
The Record reports that Kimsuky, also known as APT43, compromised South Korean collaborative-work software vendors in 2025 and early 2026, then breached some of their customers. ENKI WhiteHat researchers described one compromise through an exposed mail server and remote code execution vulnerability, and another through employee social engineering. For customers of shared groupware platforms, this is not an abstract espionage story. It is supplier compromise wearing a legitimate software relationship.
The Record, citing ENKI WhiteHat, reports that North Korea-linked Kimsuky compromised South Korean collaborative-work software vendors in 2025 and early 2026, then used that access against the vendors’ customers: https://therecord.media/kimsuky-north-korea-espionage-groupware-companies. One vendor was reportedly breached through an externally accessible mail server and a remote code execution vulnerability. Another was compromised through social engineering of an employee, followed by deployment of remote access tools on the employee’s PC.
For the customer, the uncomfortable part is not the malware family name. The report says the attackers deployed Gomir and newer variants after initial access, but the more durable lesson is about trust boundaries. A groupware vendor sits in the communication layer of an organization. If that supplier is compromised, the attacker may inherit context, credentials, update paths, or customer-facing access that looks cleaner than a normal phishing email from a stranger.
This also fits a pattern governments have already warned about. CISA, FBI and U.S. Cyber Command described Kimsuky’s reliance on spearphishing and social engineering against global intelligence targets in a 2020 advisory: https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a. Seoul and London later warned that North Korean state-linked actors were increasing software supply-chain attacks: https://therecord.media/south-korea-uk-warning-supply-chain-attacks-north-korea. The new report is narrower, but not surprising.
The Monday work is boring and necessary: inventory which collaboration and groupware vendors can touch mail, files, identity, or internal messaging; verify whether exposed vendor-side services create customer risk; and make supplier incident notice clauses operational, not decorative. Supply-chain risk programs tend to look tidy in procurement files. This is the version where the attacker reads the file and walks through the vendor door anyway.
Published ·Deep Fathom