A massive data leak, which took place in early September 2025 and is attributed to a cybercriminal known as “Kim”, gave us a glimpse into the operational playbook of the Kimsuky (APT43) hackers.

The leak, which includes terminal history files, phishing domains, OCR workflows, compiled stagers, and a full Linux rootkit, revealed a campaign focused on credentials and targeting South Korean government PKI systems and Taiwanese academic networks.
The artifacts include bash histories that demonstrate shellcode deployment with NASM, along with OCR commands used to extract settings from Korean-language PDF documents related to PKI and VPN deployments.
The scope of the leak highlights an evolution in technique, combining traditional rootkit persistence with advanced adversary-in-the-middle phishing.
See also: Hackers abuse Amazon SES for phishing attacks
Domaintools analysts discovered an extensive network of malicious sites that mimic official Korean portals, including nid-security.com and webcloud-notice.com. These sites used real-time TLS proxies to intercept credentials (a significant shift from document collection via active AiTM interception).
The leak also contained PAM logs describing administrative password rotations—tagged 백이완료 (“change complete”)—for high-privilege accounts such as oracle, svradmin, and app_adm01. Plain-text GPKI key files, such as 136백운규001_env.key, confirmed the direct breach of the South Korean government’s cryptographic assets.
Beyond South Korea, Domaintools researchers noted that the perpetrator conducted targeted reconnaissance against Taiwanese government and research institutions, gaining access to .git directories to enumerate exposed source repositories and collect embedded secrets.

The presence of temporary email addresses, linked to phishing kits (along with detection logs against gitee.com and baidu.com), reflects a hybrid DPRK–PRC footprint that exploits Chinese infrastructure for staging and evasion.
See also: GhostAction campaign steals 3325 secrets in GitHub attack
Kimsuky: Infection mechanism
A closer look at the malware's infection mechanism reveals a two-stage loader that combines custom shellcode with publicly available frameworks. The initial payload is a handcrafted NASM shellcode stub compiled with flags, such as -f win32, designed to allocate memory via VirtualAlloc and resolve Win32 API calls via hashed import tables.
Once memory is allocated, the loader decrypts and patches a secondary payload—often a CobaltStrike-derived stager—in the process before transferring execution.
This approach avoids signature-based detection, as the shellcode is polymorphic and API calls are masked by simple XOR hashing routines. Persistence is achieved through a custom Linux rootkit, vmmisc.ko, which hooks syscalls such as read and getdents to hide files, directories, and network sockets.
By inserting via insmod /usr/lib64/tracker-fs/vmmisc.ko, the rootkit unpacks an embedded userland backdoor binary. It then installs a SOCKS5 proxy and a password-protected PTY-based reverse shell (testtest).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The rootkit's dual-mode binary embedding technique merges the kernel module and userland executable, leaving only the .ko file on disk to prevent detection. This infection chain highlights a combination of manual tool assembly and opportunistic use of open-source repositories, such as TitanLdr and Blacklotus, demonstrating the sophisticated techniques of the Kimsuky group.
See also: PoC Exploit released for RCE vulnerability in ImageMagick
Organizations across South Korea and Taiwan should now expect multi-stage attacks, focusing first on credentials, combining low-level shellcode engineering with hidden kernel-mode implants.
The “Kim” leak is a rare window into the inner workings of an APT group, and reveals how sophisticated cyberespionage tools and methods have become. The discovery of logs, rootkits, and detailed shellcode workflows shows that Kimsuky’s attacks are not simple phishing campaigns, but combine state-sponsored techniques with a multi-layered infection chain.
Of particular interest is the targeting of PKI infrastructures and the reporting of cryptographic keys in plain text; this means that it is not just about stealing credentials, but an attempt to erode trust in government digital infrastructure itself. Such a breach can undermine a country’s national security more profoundly than any “conventional” data leak.
