Security1 distinct publisher2 min readPublished
ASEC says the North Korean group now installs Chrome Remote Desktop after AppleSeed lands, while its older VNC and RDP Wrapper activity keeps turning up in logs.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Order matters more than the tool. Every remote-access option ASEC lists arrives after AppleSeed is already resident [10], and AppleSeed on its own runs operator commands, installs further malware, logs keystrokes, captures screenshots and steals files [11]. The remote desktop session is not the way in. It is how an operator sits down at a machine that has already been taken, on a channel that does not depend on the backdoor's own HTTP command path [12].
The migration reading needs the caveat ASEC supplies itself. Customized VNC and RDP Wrapper logs are still being detected [3], and RDP Patcher was dropped in the same intrusions that produced the remote desktop installs [10], a utility that exists only because a normal Windows environment allows one RDP session per PC [14]. Count what ASEC attributes to this group and there are four distinct routes to an interactive session: Meterpreter, patched VNC, RDP modification, and now a sanctioned remote desktop service [1]. That is accumulation. A control set tuned to the first three loses coverage without any of them being abandoned.
What remains stable is everything upstream of the access tool. AppleSeed will not execute unless it is launched with 123qweASDZXC passed to /I [9], which is a hard behavioural condition rather than a hash. Two versions are in circulation, both talking to their C&C over HTTP [12]. The credential stealer writes to a fixed location under C:\ProgramData\Adobe, and the current build reaches past Chrome into Microsoft Edge and Naver Whale [13]. ASEC's own note on that stealer is the useful one: it was first identified last year and the same code keeps being reused rather than replaced [13].
That is the shape of the whole kit. AppleSeed has been detected since around 2019 [11], about six years into a campaign history that starts in 2013 [2], and the group was already hitting a Korean energy corporation in 2014 before broadening beyond South Korea in 2017 [5]. Delivery is still document-shaped: HWP, MS Office and CHM attachments in spear phishing mail [6], with WSF or JS scripts wearing document extensions and opening a decoy file so the victim sees what they expected [7]. In the cases ASEC describes, the initial delivery step was not even identified; the group was caught at the script stage by log telemetry [8].
Anyone who has been scoring Kimsuky detections by implant name has been grading the wrong column. The parts that change are the ones vendors write signatures for.
Ranked by verification strength, evidence, and original report placement.
AhnLab Security Emergency response Center (ASEC) discovered the Kimsuky threat group using Chrome Remote Desktop.
Kimsuky uses its privately developed AppleSeed malware as well as remote control malware such as Meterpreter to gain control of infected systems.
ASEC says logs of the group using customized VNC or remote control tools such as RDP Wrapper continue to be detected.
Kimsuky is deemed to be supported by North Korea and has been active since 2013.
Kimsuky first attacked North Korea-related research institutes in South Korea, attacked a Korean energy corporation in 2014, and since 2017 has targeted countries other than South Korea.
Kimsuky has mainly been using HWP and MS Office document files or CHM files in malware distribution, delivered as spear phishing email attachments.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party vendor telemetry, single source, no IOCs
Claims rest on AhnLab Smart Defense logs and ASEC's own malware analysis, which is direct primary evidence with concrete artefacts (launch argument, credential file paths, PDB string, termsrv.dll patching mechanics). It is weakened by having exactly one publisher in the cluster, no hashes or C&C indicators in the supplied text, an explicitly unidentified initial access vector, and undated relative references such as 'last year'.
Confirmed in-the-wild use, scale undisclosed
Attacker-side adoption is confirmed rather than hypothetical: ASEC observed Chrome Remote Desktop installations in recent cases and reports continued detection of VNC, RDP Wrapper, RDP Patcher and the upgraded Infostealer. Adoption cannot be scored higher because no victim counts, sectors, geographies or campaign volumes are disclosed, so breadth is unknown.
Slightly overstated framing, well-grounded substance
The technical substance matches the evidence closely, and the report is candid about what it does not know. Mild overstatement comes from the narrative framing of a toolkit that is 'never retired' and from presenting Chrome Remote Desktop use as a notable shift when it is described only as observed in recent cases with no scope, while the initial access vector remains unidentified.
Vendor research blog reporting on its own telemetry
AhnLab publishes this on its own security blog and grounds the finding in AhnLab Smart Defense detections, so there is a commercial interest in demonstrating detection coverage of a high-profile state-linked actor. The incentive is moderate rather than severe: the post supplies checkable technical artefacts and explicitly states the limits of what was identified, and no pricing, product upsell or customer claim is made in the supplied text.
Credible primary reporting, uncorroborated and unscoped
Confidence is moderate: the reporting entity has direct visibility and offers verifiable artefacts, and the individual technical claims are internally consistent. It is held down by single-publisher sourcing, absent IOCs, undisclosed victim scope, vague time anchors, and an unknown initial access path.
security
Kimsuky keeps picking RDP, which puts detection on configuration instead of files1 distinct publisher
build
Three ways to ask who embedded your iframe, and only one the host cannot switch off1 distinct publisher
invest
Mozilla's pitch against Gemini-wired Chrome is an off switch and a search deal with Exa2 distinct publishers
build
height:auto is animatable now, so your max-height ceiling is a bug you can delete1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026