Kimsuky — APT Profile
Kimsuky is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Its operations have overlapped with other DPRK actors, likely due to ad hoc collaboration or limited resource sharing. Because of overlapping operations, some researchers group a wide range of North Korean state-sponsored cyber activity under the broader Lazarus Group umbrella rather than tracking separate subgroup or cluster distinctions. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models to assist with vulnerability research, scripting, social engineering and reconnaissance.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Operation Stolen Pencil, G0086, Sparkling Pisces
IntelFusions coverage (14)
- North Korea's hacking machine is bigger than Lazarus 2026-09-07 · Nation-State
- North Korean spies hid a backdoor inside a load balancer 2026-09-04 · Nation-State
- Fake seafood order hides North Korean spy script 2026-09-02 · Nation-State
- Shortcut files became the top APT lure in South Korea 2026-08-28 · Nation-State
- State hackers now log in instead of dropping malware 2026-08-20 · Nation-State
- State-backed hackers hide attacks inside AI tools and trusted cloud apps 2026-07-14 · Nation-State
- ToddyCat hackers steal corporate Gmail access with a stealthy new tool 2026-06-30 · Nation-State
- North Korean hackers flood South Korea with booby-trapped shortcut files 2026-06-29 · Nation-State
- Patchwork hackers deploy a stealthy new in-memory RAT in China-themed attacks 2026-06-17 · Nation-State
- Kimsuky Abuses GitHub as C2 Infrastructure: Hardcoded Private Tokens Enable Malware Delivery and Exfiltration via Nine Private Repositories 2026-02-16 · Nation-State
- Kimsuky Deploys HttpTroy Backdoor via VPN Invoice Lure: Three-Stage Chain Using MemLoad and COM-Based Persistence 2026-02-16 · Nation-State
- APT37 Deploys Rust-Based Backdoor and Python Loader in Targeted Campaign Against South Korean Dissidents 2026-02-16 · Nation-State
- Kimsuky's LNK-to-PowerShell Espionage Chain: Credential Theft, Keylogging, and Exfiltration Targeting South Korean Government 2026-02-16 · Nation-State
- Kimsuky Adds Chrome Remote Desktop to Remote Control Arsenal Alongside AppleSeed, RDP Patcher, and Ngrok 2026-02-16 · Nation-State
Tools & malware
- Amadey Loader
- AppleSeed Backdoor
- BabyShark Backdoor
- Brave Prince Remote Access Trojan
- CSPY Downloader Downloader
- gh0st RAT Remote Access Trojan
- GoBear Backdoor
- Gold Dragon Backdoor
- Gomir Backdoor
- KGH_SPY Backdoor
- Mimikatz Credential Harvesting
- NOKKI Downloader
- PsExec Remote Execution
- QuasarRAT Remote Access Trojan
- schtasks Persistence
- TRANSLATEXT Browser Extension
- Troll Stealer Infostealer
Vendor research
- Kimsuky Phishing Operations Putting In Work ThreatConnect
- How Microsoft names threat actors Microsoft
- 2026 GLOBAL THREAT LANDSCAPE REPORT: Decoding the Accelerated Cyber Attack Cycle Rapid7
- Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group AhnLab
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- https://us-cert.cisa.gov/ncas/alerts/aa20-301a CISA AA
- Back to the Future: Inside the Kimsuky KGH Spyware Suite Cybereason
- Analysis of the APT Campaign ‘Smoke Screen’ targeting to Korea and US 출처: https://blog.alyac.co.kr/2243 [이스트시큐리티 알약 블로그] Est
- Kimsuky APT continues to target South Korean government using AppleSeed backdoor Malwarebytes
- From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering Proofpoint
- APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations Mandiant
- Staying ahead of threat actors in the age of AI MSFT-AI
- Springtail: New Linux Backdoor Added to Toolkit Symantec
- The “Kimsuky” Operation: A North Korean APT? Securelist
- Kimsuky Phishing Operations Putting In Work ThreatConnect
- Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group AhnLab
- Kimsuky Organization Steals Operation Stealth Power Est
- STOLEN PENCIL Campaign Targets Academia Netscout
- Cyber-espionage group uses Chrome extension to infect victims Zdnet Kimsuky
Countries linked to this actor
- North Korea origin
- South Korea targets
- Japan targets
- Germany targets