Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAT-5394

Also known as: APT-C-55, Black Banshee, Velvet Chollima, ta427, RftRAT, moonpeak, archipelago, emerald sleet, sparkling pisces, springtail, kospy, APT33, Curious Serpens, Elfin, Refined Kitten

Description

UAT-5394 operates as an advanced cyber espionage group with deep ties to the North Korean government’s intelligence apparatus. The group has been active since at least 2018, focusing on research‑intensive targets such as think‑tanks, diplomats, academics, and critical infrastructure operators. Their primary motive appears to be financial gain through intellectual property theft, ransomware launches, or selling compromised host access. Technically, UAT-5394 builds a layered architecture that incorporates staging virtual machines for payload testing, VPN nodes for internal pivoting, and custom C2 servers that use non‑standard ports (9936/9966) in addition to standard RDP channels. The organization has migrated from QuasarRAT to an XenoRAT fork called MoonPeak and frequently deploys additional RAT clones such as RftRAT and Amadey. They employ living‑off‑the‑land binaries (PsExec, ProcDump), obfuscate code via .NET state machines and modified RTF headers, and rely heavily on PowerShell scripts for persistence and delivery. UAT-5394’s operational tempo is rapid; new malware variants, IP addresses, and domain names appear periodically. Their campaigns are characterized by sophisticated phishing vectors that impersonate nuclear‑security experts, malicious blogs as download portals, VPN update exploits, and Facebook Messenger messages to expand reach. The actor demonstrates a strong focus on defensive evasion—e.g., leveraging dynamic DNS, abusing legitimate services for C2, and obfuscating command streams—which makes detection challenging.

Goals & Targeting

Targeted Sectors

Government
Education
Telecommunications
Defense
Manufacturing
Energy
Healthcare
Nuclear
Transportation
Think tank
Critical infrastructure

Targeted Countries / Regions

KP
KR
CN
US
JP

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

UAT-5394, also known as Kimsuky or Black Banshee, is a North‑Korean state sponsor that develops and deploys sophisticated RAR tools such as MoonPeak and RftRAT to target government, critical infrastructure, and academic organizations across the U.S., South Korea, Japan, China, and DPRK. Their campaigns rely on spearphishing with high‑profile subject lines, malicious blogs, VPN exploits, and social engineering via Messenger to deliver malware that leverages living‑off‑the‑land techniques and custom C2 ports. The actor continually evolves its toolset and infrastructure, making it a persistent threat to organizations in the aforementioned sectors.

Goals & Targeting

UAT-5394’s strategic objectives revolve around intelligence gathering and financial exploitation of targets in high‑visibility sectors. By compromising government entities, defense contractors, and academic institutions, the group seeks to exfiltrate sensitive data that can be leveraged for geopolitical advantage or sold on illicit markets. Their targeting profile spans the public sector (government agencies), research communities (think‑tanks), critical infrastructure operators (energy, telecoms), and transportation or nuclear facilities, reflecting a mix of political influence operations with economic motives.

Enhanced Description

Key Capabilities

  • Spearphishing using nuclear‑security expert personas
  • Malicious blog delivery vector
  • VPN update vulnerability exploitation
  • Facebook Messenger exploitation
  • Android mobile malware targeting
  • Multiple RAT development (MoonPeak, XenoRAT‑based variants, RftRAT, Amadey)
  • Credential dumping with Mimikatz
  • Remote execution via PsExec and other living‑off‑the‑land tools
  • Use of .NET state machines for obfuscation
  • Custom C2 on non‑standard ports 9966/9936
  • Rapid malware and infrastructure evolution
  • Staging virtual machines for payload testing

MITRE ATT&CK Tactics

Initial Access
Execution
Credential Access
Command and Control
Defense Evasion
Persistence

ATT&CK Techniques

T1071.003
T1069.003
T1055
T1003.004
T1059.005
T1566.001
T1566.002
T1076
T1043
T1059.001
T1027
T1041

Software / Tooling

MoonPeak
XenoRAT
RftRAT
Amadey
AppleSeed backdoor
BabyShark
BITTERSWEET
CSPY Downloader
FlowerPower
Gh0st RAT
Gold Dragon
Grease
KGH_SPY
KimJongRAT
KPortScan
MailPassView
Mechanical
Mimikatz
MyDogs
Network Password Recovery
ProcDump
PsExec
ReconShark
Remote Desktop PassView
SHARPEXT
SmallTiger
SniffPass
SWEETDROP
TODDLERSHARK
TRANSLATEXT
Troll Stealer
VENOMBITE
WebBrowserPassView
xRAT
Living off the Land
AutoIt

Campaigns & Victims

UAT-5394 exhibits a high‑frequency campaign cadence, with new malware variants and command‑and‑control infrastructure emerging on a monthly basis. Attacks typically begin with targeted spearphishing or blog‑based delivery that deploys MoonPeak or related RATs to the victim endpoint. Once inside, the actor leverages RDP and VPN nodes for lateral movement to internal networks, collecting credentials and exfiltrating data via stealthy C2 channels on dedicated ports. Victim profiles skew toward high‑value research, government, and critical infrastructure sectors across U.S., South Korea, Japan, China, and DPRK, indicating a blend of geopolitical sabotage and espionage with potential for monetization.

IOC Patterns

  • Public e‑mail server used for C&C
  • Spearphishing emails with nuclear‑security expert persona
  • Malicious blogs as delivery vector
  • VPN software update vulnerability exploitation
  • Facebook Messenger exploitation
  • Android device targeting indicators
  • Custom C2 on ports 9966/9936
  • RDP usage on port 3389 to set up hosts
  • Modified RTF file payloads with GZIP header
  • Known malicious domains (pumaria.store, yoiroyse.store, demo-cloud.space)
  • Malicious IP addresses (104.194.152.251, 95.164.86.148, etc.)

Recommended Actions

  • Enforce DMARC, DKIM and SPF to mitigate email spoofing.
  • Educate users on spearphishing with high‑profile subject lines.
  • Apply timely patches for VPN clients and other software.
  • Monitor and filter traffic to/from malicious blogs and known C&C domains.
  • Implement multi‑factor authentication especially for VPN access.
  • Detect and block usage of legitimate tools (PsExec, ProcDump) used by attackers.
  • Deploy endpoint detection capable of spotting RAT signatures and credential dumping activities.
  • Block inbound traffic on ports 9966, 9936, and 3389 except from trusted network segments.
  • Monitor and log RDP connections for anomaly detection.
  • Implement DNS filtering to block resolution of known malicious domains such as pumaria.store and yoiroyse.store.
  • Subscribe to threat intelligence feeds that include the identified IPs and domain names.
  • Block or monitor execution of unknown PowerShell scripts.
  • Implement file integrity monitoring for RTF and GZIP files to detect header modifications.
  • Restrict outbound traffic on ports known to be used by MoonPeak C2 servers.
  • Deploy IDS/IPS rules targeting communication patterns associated with MoonPeak C2.

Suggested Tags

north_korean
APT
Kimsuky
UAT-5394
MoonPeak
RftRAT
Amadey
spearphishing
command_and_control_via_email
malicious_blog_delivery
vpn_exploit
facebook_messenger_exploit
android_malware
credential_dumping
living_off_the_land
xeno_rat
remote_access_trojan
mitre_att_k
c2_infrastructure
staging_environment

Confidence Assessment

The analysis is based on multiple reputable sources, including Palo Alto Networks Unit42, NCSC reports, and open‑source threat feeds. We have high confidence in the attribution to a North Korean state actor, the existence of MoonPeak and related RATs, and the identified delivery methods. However, gaps remain regarding precise operational timelines, internal infrastructure specifics, and the full extent of financial‑gain motivations. Continuous monitoring is advised to capture emerging variants and updated IOC sets.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 16 Domain 3 IPv4 Address 1

References

  1. attack.mitre.org — Cited by web research for: Interception
  2. apt.etda.or.th — Cited by web research for: PowerShell
  3. blog.talosintelligence.com — Cited by web research for: QuasarRAT
  4. blog.talosintelligence.com — Cited by web research for: Telecommunications
  5. https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academia — Cited by AI analysis.
  6. https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/ — Cited by AI analysis.
  7. https://unit42.paloaltonetworks.com/babyshark-malware-part-two-attacks-continue-using-kimjongrat-and-pcrat/ — Cited by AI analysis.
  8. https://www.zdnet.com/article/north-korean-state-hackers-target-retired-diplomats-and-military-officials/ — Cited by AI analysis.
  9. https://securelist.com/apt-trends-report-q1-2021/101967/ — Cited by AI analysis.
  10. https://blog.malwarebytes.com/threat-analysis/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/ — Cited by AI analysis.
  11. https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html — Cited by AI analysis.
  12. https://medium.com/s2wblog/unveil-the-evolution-of-kimsuky-targeting-android-devices-with-newly-discovered-mobile-malware-280dae5a650f — Cited by AI analysis.
  13. https://www.proofpoint.com/us/blog/threat-insight/social-engineering-dmarc-abuse-ta427s-art-information-gathering — Cited by AI analysis.
  14. https://asec.ahnlab.com/en/47585/ — Cited by AI analysis.
  15. https://therecord.media/north-korea-apt-kimsuky-attacks — Cited by AI analysis.
  16. https://asec.ahnlab.com/en/52970/ — Cited by AI analysis.
  17. https://asec.ahnlab.com/en/59590/ — Cited by AI analysis.
  18. https://www.securonix.com/blog/securonix-threat-research-security-advisory-new-deepgosu-attack-campaign/ — Cited by AI analysis.
  19. https://www.bleepingcomputer.com/news/security/north-korean-hackers-exploit-vpn-update-flaw-to-install-malware/ — Cited by AI analysis.
  20. https://thehackernews.com/2024/05/north-korean-hackers-exploit-facebook.html — Cited by AI analysis.
  21. https://www.security.com/threat-intelligence/springtail-kimsuky-backdoor-espionage — Cited by AI analysis.
  22. https://www.securonix.com/blog/analyzing-deepdrive-north-korean-threat-actors-observed-exploiting-trusted-platforms-for-targeted-attacks/ — Cited by AI analysis.
  23. https://asec.ahnlab.com/en/86535/ — Cited by AI analysis.
  24. https://asec.ahnlab.com/en/88132/ — Cited by AI analysis.
  25. https://securelist.com/the-kimsuky-operation-a-north-korean-apt/57915/ — Cited by AI analysis.
  26. https://securityintelligence.com/media/recent-activity-from-itg16-a-north-korean-threat-group/ — Cited by AI analysis.
  27. https://us-cert.cisa.gov/ncas/alerts/aa20-301a — Cited by AI analysis.
  28. https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite — Cited by AI analysis.
  29. https://www.darkreading.com/operations/how-north-korean-apt-kimsuky-is-evolving-its-tactics/d/d-id/1340956 — Cited by AI analysis.
  30. https://boho.or.kr/filedownload.do?attach_file_seq=2695&attach_file_id=EpF2695.pdf — Cited by AI analysis.
  31. https://asec.ahnlab.com/en/30532/ — Cited by AI analysis.
  32. https://asec.ahnlab.com/en/60054/ — Cited by AI analysis.
  33. https://asec.ahnlab.com/wp-content/uploads/2023/03/2022-Threat-Trend-Report-on-Kimsuky.pdf — Cited by AI analysis.
  34. https://asec.ahnlab.com/wp-content/uploads/2023/03/Unique-characteristics-of-Kimsuky-groups-spear-phishing-emails.pdf — Cited by AI analysis.
  35. https://mandiant.widen.net/s/zvmfw5fnjs/apt43-report — Cited by AI analysis.
  36. https://blog.google/threat-analysis-group/how-were-protecting-users-from-government-backed-attacks-from-north-korea/ — Cited by AI analysis.
  37. https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/ — Cited by AI analysis.
  38. https://www.rapid7.com/blog/post/2024/03/20/the-updated-apt-playbook-tales-from-the-kimsuky-threat-actor-group/ — Cited by AI analysis.
  39. https://media.defense.gov/2024/May/02/2003455483/-1/-1/0/CSA-NORTH-KOREAN-ACTORS-EXPLOIT-WEAK-DMARC.PDF — Cited by AI analysis.

Intel Summary

13

Techniques

69

Tools

0

Campaigns

38

IOCs

0

Observed Data

9

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
north_korean
Kimsuky
UAT-5394
MoonPeak
RftRAT
Amadey
spearphishing
command_and_control_via_email
malicious_blog_delivery
vpn_exploit
facebook_messenger_exploit
android_malware
credential_dumping
living_off_the_land
xeno_rat
remote_access_trojan
mitre_att_k
c2_infrastructure
staging_environment

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.