HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

North Korean APT Kimsuky Breaches South Korean Groupware Vendors, Exposes Customer Data

Kimsuky leveraged a remote‑code‑execution flaw and phishing to infiltrate two South Korean SaaS groupware providers, stealing server‑level information belonging to their customers. The incident underscores the need for continuous vendor‑risk monitoring and SOC 2‑ready audit evidence.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

North Korean APT Kimsuky Breaches South Korean Groupware Vendors, Exposes Customer Data

What Happened — Kimsuky (APT 43) leveraged a remote‑code‑execution flaw in an externally‑facing mail server and a phishing‑based social‑engineering attack to gain footholds in two South Korean groupware SaaS vendors. After initial access, the actors deployed the Gomir malware family and custom variants, moved laterally, harvested employee credentials (thanks to missing MFA), and stole server‑level information belonging to the vendors’ customers.

Why It Matters for Compliance & Audit Readiness

  • This supply‑chain breach illustrates why SOC 2 vendor‑management controls (CC6.1 – CC6.3) must be continuously monitored and documented.
  • Evidence of third‑party risk assessments, MFA enforcement, and real‑time security‑posture dashboards become critical audit artifacts after a breach.
  • Verisq’s Vendor Risk capability provides the continuous monitoring and evidence‑collection needed to keep your SOC 2 audit trail intact when a supplier is compromised.

Who Is Affected – SaaS groupware providers in South Korea and their enterprise customers (technology / software‑as‑a‑service sector).

Recommended Actions

  • Initiate an immediate third‑party risk review of all groupware and collaboration‑tool suppliers.
  • Verify that vendors enforce MFA, patch known RCE vulnerabilities, and provide continuous security‑posture evidence.
  • Map the incident to SOC 2 CC6 controls, collect logs, and retain evidence for audit readiness.

Source: The Record

Technical Notes – Attack vectors included a remote‑code‑execution vulnerability in a mail server, phishing‑based credential harvesting, and lack of MFA. Malware families observed: Gomir and new variants. Stolen data: customer server configuration and credentials. Source: The Record

📰 Original Source
https://therecord.media/kimsuky-north-korea-espionage-groupware-companies

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →