Published · 1h agoSecurity2 min read
Four of Kimsuky's remote-control channels are software defenders already approved
AhnLab's case files put the North Korean spear-phishing group on RDP, RDP Wrapper, TightVNC and Chrome Remote Desktop. Its custom code mostly exists to make those work.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- AhnLab's ASEC reported logs showing the Kimsuky group installing Chrome Remote Desktop to remotely control infected systems, after AppleSeed was used to install further malware.
- Kimsuky used AppleSeed to install other malware including infostealers, RDP Patcher and Ngrok.
- Kimsuky is deemed to be supported by North Korea, has been active since 2013, and usually spear-phishes the national defence, diplomatic and academic sectors, defence and media industries and national organisations, with the goal of exfiltrating internal information and technology.
- ASEC says Kimsuky's most commonly used remote control method is RDP; where RDP is absent the open-source RDP Wrapper is installed, a user account is added for RDP access, and additional malware conceals the added account and configures multiple RDP sessions.
- ASEC recorded cases where TinyNuke (public malware) or TightVNC (an open-source VNC tool) were customised and used in Kimsuky attacks.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Count what the bespoke code in ASEC's Kimsuky write-ups actually does. RDP Patcher is needed because a normal Windows box allows one RDP session at a time [7]. Other components add an account for RDP access, then conceal it and configure multiple sessions [4]. RevClient, which ASEC describes as newly built, waits on the command server to add user accounts or switch on port forwarding [6]. None of that is a channel. It is glue for four channels the target already owns or can fetch free [18], from a group AhnLab assesses is North Korean-supported and has been running since 2013 against defence, diplomatic and academic targets [3].
MITRE's own catalogue says the quiet part: this class of software is commonly used by real technical support and so may be permitted by application control [8], and the capability now ships inside things like Zoom and Chrome [9].
The bypass is not clever. CISA, NSA and MS-ISAC found actors skipping installation entirely, running AnyDesk and ScreenConnect as portable executables in the user's context, which defeats controls that audit or block installs [11]. That campaign was a refund scam [10], found on two federal civilian networks and then many more [13], and CISA's own read is that such access can be sold on to APT actors [12].
Microsoft's February 2026 case moves the trust decision again: one Extended Validation certificate issued to TrustConnect Software PTY LTD [14] covering five distinct filenames [17], with the payload being three RMM products [15] and persistence held by a service plus a Run key called TrustConnectAgent pointed at an Adobe path [19].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
AhnLab's ASEC reported logs showing the Kimsuky group installing Chrome Remote Desktop to remotely control infected systems, after AppleSeed was used to install further malware.
- [2]
Kimsuky used AppleSeed to install other malware including infostealers, RDP Patcher and Ngrok.
- [3]
Kimsuky is deemed to be supported by North Korea, has been active since 2013, and usually spear-phishes the national defence, diplomatic and academic sectors, defence and media industries and national organisations, with the goal of exfiltrating internal information and technology.
- [4]
ASEC says Kimsuky's most commonly used remote control method is RDP; where RDP is absent the open-source RDP Wrapper is installed, a user account is added for RDP access, and additional malware conceals the added account and configures multiple RDP sessions.
- [5]
ASEC recorded cases where TinyNuke (public malware) or TightVNC (an open-source VNC tool) were customised and used in Kimsuky attacks.
- [6]
A newly discovered Kimsuky malware named RevClient by the threat actor receives commands from a C&C server and can add user accounts or enable port forwarding.
Sources & coverage · 5 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- news.risky.biz1h agoExpired cards can be used for new transactions
- asec.ahnlab.com1h agoKimsuky Threat Group Using Chrome Remote Desktop - ASEC BLOG
- asec.ahnlab.com1h agoKimsuky Threat Group Uses RDP to Control Infected Systems - ASEC BLOG


