Also known as: APT-C-55, Black Banshee, Velvet Chollima, ta427, RftRAT, moonpeak, archipelago, emerald sleet, sparkling pisces, springtail, kospy, APT33, Curious Serpens, Elfin, Refined Kitten
UAT-5394 operates as an advanced cyber espionage group with deep ties to the North Korean government’s intelligence apparatus. The group has been active since at least 2018, focusing on research‑intensive targets such as think‑tanks, diplomats, academics, and critical infrastructure operators. Their primary motive appears to be financial gain through intellectual property theft, ransomware launches, or selling compromised host access. Technically, UAT-5394 builds a layered architecture that incorporates staging virtual machines for payload testing, VPN nodes for internal pivoting, and custom C2 servers that use non‑standard ports (9936/9966) in addition to standard RDP channels. The organization has migrated from QuasarRAT to an XenoRAT fork called MoonPeak and frequently deploys additional RAT clones such as RftRAT and Amadey. They employ living‑off‑the‑land binaries (PsExec, ProcDump), obfuscate code via .NET state machines and modified RTF headers, and rely heavily on PowerShell scripts for persistence and delivery. UAT-5394’s operational tempo is rapid; new malware variants, IP addresses, and domain names appear periodically. Their campaigns are characterized by sophisticated phishing vectors that impersonate nuclear‑security experts, malicious blogs as download portals, VPN update exploits, and Facebook Messenger messages to expand reach. The actor demonstrates a strong focus on defensive evasion—e.g., leveraging dynamic DNS, abusing legitimate services for C2, and obfuscating command streams—which makes detection challenging.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAT-5394, also known as Kimsuky or Black Banshee, is a North‑Korean state sponsor that develops and deploys sophisticated RAR tools such as MoonPeak and RftRAT to target government, critical infrastructure, and academic organizations across the U.S., South Korea, Japan, China, and DPRK. Their campaigns rely on spearphishing with high‑profile subject lines, malicious blogs, VPN exploits, and social engineering via Messenger to deliver malware that leverages living‑off‑the‑land techniques and custom C2 ports. The actor continually evolves its toolset and infrastructure, making it a persistent threat to organizations in the aforementioned sectors.
Goals & Targeting
UAT-5394’s strategic objectives revolve around intelligence gathering and financial exploitation of targets in high‑visibility sectors. By compromising government entities, defense contractors, and academic institutions, the group seeks to exfiltrate sensitive data that can be leveraged for geopolitical advantage or sold on illicit markets. Their targeting profile spans the public sector (government agencies), research communities (think‑tanks), critical infrastructure operators (energy, telecoms), and transportation or nuclear facilities, reflecting a mix of political influence operations with economic motives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAT-5394 exhibits a high‑frequency campaign cadence, with new malware variants and command‑and‑control infrastructure emerging on a monthly basis. Attacks typically begin with targeted spearphishing or blog‑based delivery that deploys MoonPeak or related RATs to the victim endpoint. Once inside, the actor leverages RDP and VPN nodes for lateral movement to internal networks, collecting credentials and exfiltrating data via stealthy C2 channels on dedicated ports. Victim profiles skew toward high‑value research, government, and critical infrastructure sectors across U.S., South Korea, Japan, China, and DPRK, indicating a blend of geopolitical sabotage and espionage with potential for monetization.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple reputable sources, including Palo Alto Networks Unit42, NCSC reports, and open‑source threat feeds. We have high confidence in the attribution to a North Korean state actor, the existence of MoonPeak and related RATs, and the identified delivery methods. However, gaps remain regarding precise operational timelines, internal infrastructure specifics, and the full extent of financial‑gain motivations. Continuous monitoring is advised to capture emerging variants and updated IOC sets.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
69
Tools
0
Campaigns
38
IOCs
0
Observed Data
9
Tactics