On March 20, Korea’s National Intelligence Service (NIS) and Germany’s Federal Office for the Protection of the Constitution (Bundesamt für Verfassungsschutz, BfV) released a joint security advisory related to the Kimsuky hacker group. According to the joint security advisory, the Kimsuky hacker group exploited the extension feature of Chromium browsers and the app developer support feature for Android in an attack campaign to steal account credentials. Although their primary targets are Korean Peninsula and North Korea experts, it was stated that it could expand to unspecified individuals around the world.
- Title: Warning on KIMSUKY Cyber Actor’s Recent Cyber Campaigns against Google’s Browser and App Store Services
- Security Advisory: Korea’s National Cyber Security Center (NCSC) Link
AhnLab detects the Indicator of Compromise (IoC) files published in the joint advisory in the following way.
|IoC MD5||Detection Name||Engine Version|
|012d5ffe697e33d81b9e7447f4aa338b||Configuration files are not targeted for detection||–|
Subscribe to AhnLab’s next-generation threat intelligence platform ‘AhnLab TIP’ to check related IOC and detailed analysis information.