North Korean APT Kimsuky Uses forceCopy Malware to Steal Browser-Stored Credentials

Feb 6, 2025

The North Korea-linked nation-state hacking group known as Kimsuky has been observed conducting spear-phishing attacks to deliver an information stealer malware named forceCopy, according to new findings from the AhnLab Security Intelligence Center (ASEC).
The attacks commence with phishing emails containing a Windows shortcut (LNK) file that’s disguised as a Microsoft Office or PDF document.

Get Free Report & Network Analysis

Please check your email for the free report.