Kimsuky — APT Profile
Kimsuky is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Its operations have overlapped with other DPRK actors, likely due to ad hoc collaboration or limited resource sharing. Because of overlapping operations, some researchers group a wide range of North Korean state-sponsored cyber activity under the broader Lazarus Group umbrella rather than tracking separate subgroup or cluster distinctions. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models to assist with vulnerability research, scripting, social engineering and reconnaissance.Also tracked as
Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail
Tools & malware
- Amadey Loader
- AppleSeed Backdoor
- BabyShark Backdoor
- Brave Prince Remote Access Trojan
- CSPY Downloader Downloader
- gh0st RAT Remote Access Trojan
- GoBear Backdoor
- Gold Dragon Backdoor
- Gomir Backdoor
- KGH_SPY Backdoor
- Mimikatz Credential Harvesting
- NOKKI Downloader
- PsExec Remote Execution
- QuasarRAT Remote Access Trojan
- schtasks Persistence
- TRANSLATEXT Browser Extension
- Troll Stealer Infostealer
Vendor research
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group AhnLab
- How Microsoft names threat actors Microsoft
- 2026 GLOBAL THREAT LANDSCAPE REPORT: Decoding the Accelerated Cyber Attack Cycle Rapid7
- Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group AhnLab
- Kimsuky Organization Steals Operation Stealth Power Est
- STOLEN PENCIL Campaign Targets Academia Netscout
- Cyber-espionage group uses Chrome extension to infect victims Zdnet Kimsuky
- https://us-cert.cisa.gov/ncas/alerts/aa20-301a CISA AA
- Back to the Future: Inside the Kimsuky KGH Spyware Suite Cybereason
- Analysis of the APT Campaign ‘Smoke Screen’ targeting to Korea and US 출처: https://blog.alyac.co.kr/2243 [이스트시큐리티 알약 블로그] Est
- Kimsuky APT continues to target South Korean government using AppleSeed backdoor Malwarebytes
- From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering Proofpoint
- APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations Mandiant
- Staying ahead of threat actors in the age of AI MSFT-AI
- Springtail: New Linux Backdoor Added to Toolkit Symantec
- The “Kimsuky” Operation: A North Korean APT? Securelist
- Kimsuky Phishing Operations Putting In Work ThreatConnect