2025 CJ OliveNetworks — code-signing certificate theft attributed to Kimsuky; used in targeted malware
Data compromised
PKI signing assets (firm stated no PII in cert bundle)
Technical writeup
CJ OliveNetworks confirmed digital certificate theft leveraged to sign malware in May 2025, with KISA notification and Kimsuky attribution in South Korean press; certificate was revoked and firm asserted no personal data inside the stolen signing material.
Root cause
Certificate material theft enabling signed-malware distribution chain