Kimsuky’s Evolving Phishing Playbook: URL Tactics and Global Deception

Amber | Attack Report
Download PDF

The North Korea-aligned threat actor Kimsuky has been implicated in a wave of phishing attacks targeting credential theft. These campaigns involve email messages originating from Russian sender addresses, employing sophisticated tactics to evade detection. While email phishing remains a widespread global threat, URL phishing, which does not involve malware attachments in inbox emails, exclusively a malware-less attack often flies under the radar. Unlike traditional phishing attempts that rely on malware-laden links, Kimsuky frequently leverages URL phishing tactics, particularly in Korea, demonstrating a strategic focus on this less-detected attack vector.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox