DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // KIMSUKY-BIRDTROY-DRIVETROYFIRST SEEN: 2012 (BirdTroy/DriveTroy campaign: NOV 2025)

KIMSUKY

ALSO KNOWN AS: APT43, Emerald Sleet, Velvet Chollima, Black Banshee, Thallium, TA427, Springtail, GreenCraig
FROM:DMZ INTELLIGENCE DESK
ORIGIN:North Korea (DPRK) — Reconnaissance General Bureau (RGB)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2012 (BirdTroy/DriveTroy campaign: NOV 2025)
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL82/100
RESOURCES90/100
PERSISTENCE90/100
STEALTH90/100
IMPACT82/100

ENKI WhiteHat published a full technical analysis on July 20, 2026, disclosing that Kimsuky spent nearly a year embedded inside at least two South Korean enterprise groupware vendors, deploying two previously unknown Linux backdoors — BirdTroy and DriveTroy — that use HTTP/3 QUIC transport and Google Drive API for C2 respectively, making both families near-invisible to conventional network security tooling. By compromising the vendors, Kimsuky silently pivoted to downstream customers without triggering alerts.

Strategic espionage targeting South Korean defense, government, and technology sectors; intelligence collection for DPRK leadership

Supply chain compromise via mail-server RCE and employee social engineering, Go-based Linux backdoors (BirdTroy/DriveTroy/Gomir family), HTTP/3 QUIC C2 to evade firewalls, Google Drive API abuse for C2 and exfiltration using embedded OAuth tokens, DWAgent RMM tool for persistence, credential harvesting via modified groupware login pages, proxy tool deployment

SOUTH KOREAN GOVERNMENT
DEFENSE
GROUPWARE/SAAS VENDORS
THINK TANKS
CRITICAL INFRASTRUCTURE

Google Drive API C2 (DriveTroy — indistinguishable from legitimate traffic), HTTP/3 QUIC transport on UDP/443 (BirdTroy — bypasses TCP-based inspection), systemd/cron persistence, DWAgent RMM; C2 infrastructure hashes, YARA rules and IoCs published by ENKI WhiteHat July 20, 2026

FILE DATE: NOV 2025
South Korean Groupware Vendor Intrusion
Kimsuky breached at least two South Korean collaborative-work software vendors via mail-server RCE exploitation and spear-phishing, deploying BirdTroy and DriveTroy Linux backdoors and modifying login pages to harvest employee credentials.
FILE DATE: JUL 2026
BirdTroy/DriveTroy Public Disclosure
ENKI WhiteHat published a full technical report on July 20, 2026 ███████████████████ DriveTroy as new Gomir-family variants, providing C2 infrastructure, malware hashes, embedded OAuth credentials, and YARA rules.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn