Kimsuky Hijacks Chrome Remote Desktop and AnyDesk for Persistent Access
The North Korean threat group Kimsuky has learned to leave behind multiple pathways back into a compromised computer, with several of them disguised as entirely ordinary software. Researchers at ENKI WhiteHat uncovered a series of targeted phishing campaigns against users in South Korea and Japan, active throughout the first half of 2026.
The Infection Chain: A Malicious LNK Disguised as a PDF
Victims received emails containing a link to an archive hosted on OneDrive. Inside sat a malicious LNK shortcut disguised as a document. Upon execution, the shortcut displayed a genuine PDF file as a decoy, while quietly downloading a script and establishing contact with a command-and-control server in the background. Windows then created a scheduled task designed to regularly execute PowerShell commands.
Data Theft: Keystrokes, Email, and System Reconnaissance
The malicious scripts collected information about the infected computer and its installed security software, logged keystrokes, and stole email data from both Outlook and Thunderbird. To exfiltrate the harvested data, attackers relied on both their own command-and-control infrastructure and compromised South Korean servers. Infrastructure addresses changed frequently, complicating efforts to track the campaign.
Weaponizing Legitimate Remote Access Tools
What set this operation apart was Kimsuky’s use of genuine remote access software – Chrome Remote Desktop and AnyDesk. The group installed both tools on compromised machines and linked them to its own credentials. To launch Chrome Remote Desktop with elevated privileges, attackers bypassed Windows User Account Control through the legitimate system utility fodhelper.exe.
AnyDesk, meanwhile, was aggressively hidden from the victim. A dedicated script suppressed the application’s window, removed its taskbar button, and hid its notification area icon, while a Windows scheduled task relaunched the necessary components every five minutes. This approach gave Kimsuky several independent means of maintaining control over a compromised machine, even if defenders discovered and removed some of the malicious components.
An AI-Assisted Gmail-Stealing Chrome Extension
A separate module took the form of a malicious Chrome extension designed to automatically steal Gmail messages and attachments. Within its code, researchers found detailed comments written in Korean, debug messages, and emoji. According to ENKI WhiteHat’s assessment, these characteristics point toward extensive use of generative AI in building the extension.
A Familiar Tactic in Kimsuky’s Playbook
Stealing Gmail data through browser extensions has appeared in Kimsuky’s operations before. In 2023, South Korea’s National Intelligence Service and Germany’s Federal Office for the Protection of the Constitution documented a similar scheme. The MITRE ATT&CK database also records the group’s consistent use of Chrome extensions, scheduled tasks, and legitimate remote access tools.
Recommended Detection Measures
ENKI WhiteHat advises checking for unfamiliar Windows scheduled tasks, unexpected Chrome extensions, and unexplained remote access software. Particular attention should be paid to scheduled tasks that launch PowerShell or Windows Script Host, unknown extensions requesting access to all websites, and instances of Chrome Remote Desktop or AnyDesk that users did not install themselves.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.