SUBJECT PROFILE
ENKI WhiteHat published a full technical analysis on July 20, 2026, disclosing that Kimsuky spent nearly a year embedded inside at least two South Korean enterprise groupware vendors, deploying two previously unknown Linux backdoors — BirdTroy and DriveTroy — that use HTTP/3 QUIC transport and Google Drive API for C2 respectively, making both families near-invisible to conventional network security tooling. By compromising the vendors, Kimsuky silently pivoted to downstream customers without triggering alerts.
Strategic espionage targeting South Korean defense, government, and technology sectors; intelligence collection for DPRK leadership
OPERATIONAL HISTORY
Supply chain compromise via mail-server RCE and employee social engineering, Go-based Linux backdoors (BirdTroy/DriveTroy/Gomir family), HTTP/3 QUIC C2 to evade firewalls, Google Drive API abuse for C2 and exfiltration using embedded OAuth tokens, DWAgent RMM tool for persistence, credential harvesting via modified groupware login pages, proxy tool deployment
KNOWN INFRASTRUCTURE
Google Drive API C2 (DriveTroy — indistinguishable from legitimate traffic), HTTP/3 QUIC transport on UDP/443 (BirdTroy — bypasses TCP-based inspection), systemd/cron persistence, DWAgent RMM; C2 infrastructure hashes, YARA rules and IoCs published by ENKI WhiteHat July 20, 2026