North Korea-linked Kimsuky continued spear-phishing operations built around the AppleSeed malware family, delivering payloads through JavaScript droppers, Excel macros, and malicious OneNote files disguised as business documents, surveys, purchase orders, and request forms. Researchers tied the activity to targeted campaigns against South Korean organizations as well as scientific and engineering researchers, with lures impersonating trusted institutions and decoy documents used to trigger hidden scripts. In multiple cases, the malware was launched through regsvr32.exe, fetched follow-on components with mshta.exe, and shifted persistence and installation patterns from %PROGRAMDATA% toward %APPDATA%, while adding anti-analysis checks to evade defenders.
The group also introduced AlphaSeed, a Golang-based evolution of AppleSeed that uses embedded Naver Mail cookies and the Chrome DevTools Protocol for command-and-control instead of older mailbox authentication methods. AlphaSeed was reported to persist via the Windows Run key as MS_SecSvc, collect keystrokes and screenshots, encrypt stolen data with RC4 and RSA, and exfiltrate data through Naver Mail. Across the broader intrusion chain, Kimsuky was observed using post-compromise tools including Meterpreter, TightVNC, and TinyNuke-derived HVNC, while increasingly favoring Chrome Remote Desktop over RDP; researchers also documented multi-platform artifacts, mobile AppleSeed-related components, server-side scripts, and operational links connecting these campaigns to earlier Kimsuky activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
S2W Talon discovered a suspected new Kimsuky malware sample on VirusTotal on May 6, 2023, and named it AlphaSeed based on an internal path string found in the binary.
S2W reported a Kimsuky campaign using a malicious Microsoft OneNote file impersonating Korea University's Institute for Peace and Democracy to deliver malware via a hidden VBS script.
AhnLab reports that a Golang-based Meterpreter stager was identified in the first half of 2023 as part of Kimsuky attack chains involving AppleSeed.
AhnLab states that the Golang-based AlphaSeed variant has been used in attacks since at least October 2022 and can be deployed alongside AppleSeed on the same target.
ASEC disclosed an AppleSeed campaign targeting companies related to nuclear power plants, using VBS droppers with double extensions disguised as purchase orders or request forms and opening a benign Excel bait file. The report detailed regsvr32-based DLL execution, C2 communications with ndt.info[.]gf, supported backdoor commands, and related IOCs.
ASEC disclosed signs of an AppleSeed distribution campaign targeting a specific military unit maintenance contractor using a password-protected Excel lure with a military-themed filename. The macro used mshta to fetch additional scripts that downloaded AppleSeed and executed it via regsvr32, and the report published related hashes and C2 URLs.
AhnLab reports that since early 2022, AppleSeed has been created by a dropper rather than being installed directly by JavaScript malware.
ASEC analyzed a confirmed spear-phishing attack in which a ZIP-delivered .pif dropper installed the PebbleDash backdoor, displayed a decoy PDF, and gave attackers remote control of the infected system. The report also linked related AppleSeed, VBS downloader, and Meterpreter activity to the same intrusion set and published persistence details, hashes, and C2 IOCs.
At VB2021, researchers presented "Operation Newton," an investigation reconstructing the full AppleSeed attack chain used by Kimsuky against scientific and engineering researchers, including infrastructure and multi-platform artifacts.
The VB2021 localhost content states that details about AppleSeed were previously presented at VB2019 during tracking of ongoing Kimsuky attacks.
Since 2017, Kimsuky attacks have also targeted countries beyond South Korea, broadening the group's victim geography.
AhnLab states that Kimsuky attacked a South Korean energy corporation in 2014, marking an early significant victim in the group's activity.
The North Korea-linked Kimsuky group is described as having been active since 2013, initially targeting North Korea-related research institutes in South Korea.
AhnLab published trend analysis showing Kimsuky continuing AppleSeed campaigns while adding anti-analysis argument checks, shifting installations toward %APPDATA%, introducing AlphaSeed, and increasingly using Chrome Remote Desktop for remote control.
ASEC disclosed a campaign distributing AppleSeed through JSE files masquerading as purchase orders and request forms, with execution via regsvr32 and follow-on scripts via mshta.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcemedium.com
Open sourcemedium.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourceasec.ahnlab.com
Open sourcevblocalhost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.