The Kimsuky group, linked to North Korea, has come under scrutiny after a major data leak impacting hundreds of gigabytes of internal information.
Discovery of the Data Leak
According to security researchers from Slow Mist, the Kimsuky hacker group has experienced a significant data breach. The leak reportedly occurred in early June 2025 and is traced back to two compromised systems operated under the alias 'KIM'.
Tools and Information from the Leak
The leaked data includes phishing campaign logs, browser histories, and exploitation manuals for various tools, including backdoors and malware. Notably, the leak involves tools such as TomCat and Cobalt Strike.
Kimsuky’s Long History
The Kimsuky group has been known since 2012 for cyber-espionage, targeting governments and academic institutions. They have employed various methods for intrusion, including phishing and disguising malicious files as legitimate documents.
The Kimsuky data leak underscores the growing cybersecurity threats and the necessity for vigilant monitoring of such groups. Research is ongoing.