North Korean Hackers on a Rampage: South Korea’s Crypto and Government Under Siege!
North Korea’s Kimsuky group is back with DEEP#DRIVE, a campaign targeting South Korea’s business, government, and cryptocurrency sectors. Using phishing emails and PowerShell scripts, they cleverly exploit Dropbox for payload delivery. Who knew Dropbox could be a hacker’s best friend?

Hot Take:
North Korea seems to be swapping missile launches for mouse clicks as they take the term ‘hostile takeover’ way too literally! If you were worried about your Bitcoin disappearing, maybe it’s time to worry about your forklift safety plan too. Someone alert the workplace safety inspector – looks like he’s got competition from a bunch of hackers who have a thing for heavy machinery manuals!
Key Points:
- North Korean hacker group Kimsuky targets South Korean sectors, including cryptocurrency.
- The campaign, named DEEP#DRIVE, uses clever phishing techniques with decoy documents.
- PowerShell scripts and Dropbox are employed for payload delivery and data exfiltration.
- Attackers disguise their efforts with Korean language documents to appear legitimate.
- Securonix’s investigation suggests the operation has been running since September last year.
Already a member? Log in here