Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SkidSec

Also known as: SkidSec Leaks, APT28, Pawn Storm, Fancy Bear, Sednit, gorillabotnet, moobot, muhstik, nosviak4, flodric, aisuru, kimwolf

Description

SkidSec’s publicly documented campaigns focus on exploiting unsecured network printers in South Korea to push North Korean propaganda material and gather evidence for political influence operations. After the presumed loss of their leader Govadmin, the group maintained operational momentum by mobilizing a follower community that supports various missions. The group humorously solicits financial donations from sympathizers, framing it as funding a cause, while simultaneously posing a potential data‑leak threat from compromised devices. Their tactics reflect typical hybrid warfare: deploying technical exploits such as printer vulnerabilities, using cloud infrastructure to store exfiltrated material, and leveraging well‑known malware families for lateral movement and persistence. The dual focus on ideology and financial gain demonstrates an adaptive and opportunistic approach tied closely to the geopolitical objectives of North Korea.

Goals & Targeting

Targeted Sectors

Defense
Government
Education
Energy
Financial services
Nuclear

Targeted Countries / Regions

KP
CN

AI Analysis

Grounded in web research
· 5 hours ago

Executive Summary

SkidSec is a financially‑motivated group with strong ties to North Korean propaganda efforts, targeting exposed network printers and high‑value sectors such as defense, government, energy, and finance in North Korea and China. Their operations blend technical exploits – notably printer exploitation – with social engineering and the use of common malware tools to collect evidence and potentially leak sensitive data.

Goals & Targeting

SkidSec seeks to amplify North Korean propaganda influence by reaching audiences in South Korea while simultaneously exploiting high‑value targets in defense, government, education, energy, finance, and nuclear sectors across North Korea and China. The group’s financial motive drives them to monetize compromised systems through data theft or ransomware, but their political objective is evident in the targeting of political messages and evidence collection for potential blackmail or influence operations. Typical victims are organizations exposed to publicly reachable printers and those lacking robust endpoint detection; they also target users who may comply with social engineering emails that deliver malicious attachments or links.

Enhanced Description

Key Capabilities

  • Exploits of unmanaged network printers
  • Social engineering via spear‑phishing and deceptive email forwarding rules
  • Use of Windows Management Instrumentation for lateral movement
  • Obfuscated PowerShell scripts and command line execution
  • Ingress tool transfer via legitimate utilities (BITS, netsh)
  • “Fast‑flux”-like domain churn in C2 communication
  • Data staging on cloud or bulletproof hosting domains
  • Potential use of credential dumping tools such as Mimikatz

MITRE ATT&CK Tactics

Discovery
Execution
Persistence
Privilege Escalation
Defense Evasion
Collection
Command and Control
Exfiltration

ATT&CK Techniques

T1047
T1564.008
T1530
T1059
T1114.003
T1059.001
T1027
T1204.004
T1105
T1078.004

Software / Tooling

PowerShell
Cobalt Strike
Quasar RAT
Agent Tesla
Havex RAT
Crimson
Gootloader
IcedID
SocGholish
Babuk
netsh

Campaigns & Victims

SkidSec’s campaigns are sporadic but strategically targeted, often coinciding with politically relevant events. They mobilize a network of followers who contribute custom scripts or additional delivery mechanisms. The group demonstrates an ability to adapt rapidly following leadership changes, sustaining activity by leveraging shared infrastructure and commonly‑used malware libraries. Their operational tempo has shown bursts corresponding to geopolitical tensions, suggesting a link between state objectives and attack frequency.

IOC Patterns

  • Spear-phishing emails with malicious Office attachments
  • Exploiting exposed network printers and unauthorized access
  • Domain-based C2 via fast‑flux DNS (e.g., demo-cloud.space, ransomlook.io)
  • Email forwarding rules used to obfuscate legitimate traffic
  • Use of bulletproof hosting for staging infrastructure (skidsec.org, cnc.smokemethallday.tk)
  • Malicious copy & paste technique for lateral movement

Recommended Actions

  • Implement strict access controls and logging on all network printers; disable remote printing from external sources.
  • Apply MFA to cloud accounts and monitor for anomalous API activities. Enforce least‑privilege for email routing and delete default forwarding rules at install. Deploy endpoint protection that flags obfuscated PowerShell scripts and unknown download tools. Block known malicious domains and IPs listed in IOC tables; continuously update threat feeds. Educate staff on spear-phishing and the risks of unsolicited attachments. Patch printers and network infrastructure promptly to close publicly exposed vulnerabilities.

Suggested Tags

APT
influence operations
espionage
finance‑gain
North Korea
China
printer exploitation

Confidence Assessment

The available intelligence is limited and largely fragmented, with no recent independently verified reports of SkidSec activity beyond a few domain and email IOC references. The alias list conflates multiple known state actors (e.g., APT28, Fancy Bear), creating uncertainty about attribution. While the described exploitation of exposed printers in South Korea has some corroboration, other details such as tool usage rely on generic lists derived from unrelated Malpedia entries. Consequently, confidence is moderate for activity patterns but low for precise technical capabilities and attribution specifics; further correlation with up‑to‑date incident data is needed.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. redcanary.com — Cited by web research for: T1078.004
  2. attack.mitre.org — Cited by web research for: Interception
  3. www.splunk.com — Cited by web research for: Payload
  4. github.com — Cited by web research for: Crimson
  5. https://malpedia.caad.fkie.fraunhofer.de/actors — Cited by AI analysis.
  6. https://malpedia.caad.fkie.fraunhofer.de/details/win.darkside — Cited by AI analysis.

Intel Summary

10

Techniques

41

Tools

0

Campaigns

14

IOCs

0

Observed Data

4

Tactics

Tags

Ransomware
APT
influence operations
espionage
finance‑gain
North Korea
China
printer exploitation

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.