Also known as: SkidSec Leaks, APT28, Pawn Storm, Fancy Bear, Sednit, gorillabotnet, moobot, muhstik, nosviak4, flodric, aisuru, kimwolf
SkidSec’s publicly documented campaigns focus on exploiting unsecured network printers in South Korea to push North Korean propaganda material and gather evidence for political influence operations. After the presumed loss of their leader Govadmin, the group maintained operational momentum by mobilizing a follower community that supports various missions. The group humorously solicits financial donations from sympathizers, framing it as funding a cause, while simultaneously posing a potential data‑leak threat from compromised devices. Their tactics reflect typical hybrid warfare: deploying technical exploits such as printer vulnerabilities, using cloud infrastructure to store exfiltrated material, and leveraging well‑known malware families for lateral movement and persistence. The dual focus on ideology and financial gain demonstrates an adaptive and opportunistic approach tied closely to the geopolitical objectives of North Korea.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SkidSec is a financially‑motivated group with strong ties to North Korean propaganda efforts, targeting exposed network printers and high‑value sectors such as defense, government, energy, and finance in North Korea and China. Their operations blend technical exploits – notably printer exploitation – with social engineering and the use of common malware tools to collect evidence and potentially leak sensitive data.
Goals & Targeting
SkidSec seeks to amplify North Korean propaganda influence by reaching audiences in South Korea while simultaneously exploiting high‑value targets in defense, government, education, energy, finance, and nuclear sectors across North Korea and China. The group’s financial motive drives them to monetize compromised systems through data theft or ransomware, but their political objective is evident in the targeting of political messages and evidence collection for potential blackmail or influence operations. Typical victims are organizations exposed to publicly reachable printers and those lacking robust endpoint detection; they also target users who may comply with social engineering emails that deliver malicious attachments or links.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SkidSec’s campaigns are sporadic but strategically targeted, often coinciding with politically relevant events. They mobilize a network of followers who contribute custom scripts or additional delivery mechanisms. The group demonstrates an ability to adapt rapidly following leadership changes, sustaining activity by leveraging shared infrastructure and commonly‑used malware libraries. Their operational tempo has shown bursts corresponding to geopolitical tensions, suggesting a link between state objectives and attack frequency.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence is limited and largely fragmented, with no recent independently verified reports of SkidSec activity beyond a few domain and email IOC references. The alias list conflates multiple known state actors (e.g., APT28, Fancy Bear), creating uncertainty about attribution. While the described exploitation of exposed printers in South Korea has some corroboration, other details such as tool usage rely on generic lists derived from unrelated Malpedia entries. Consequently, confidence is moderate for activity patterns but low for precise technical capabilities and attribution specifics; further correlation with up‑to‑date incident data is needed.
No campaigns linked yet.
No observed data linked yet.
10
Techniques
41
Tools
0
Campaigns
14
IOCs
0
Observed Data
4
Tactics