Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Kimsuky

Also known as: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Kimsuky, Operation Stolen Pencil, G0086, Sparkling Pisces, advanced persistent, Emerald Street, Ruby Sleet, advanced spear phishing attacks, Quishing

Description

Kimsuky operates as a highly coordinated North‑Korean APT group whose mission is primarily state espionage. Their operations begin with meticulous reconnaissance—collecting organizational hierarchy, staff lists and public statements from government sites, think‑tank portals and academic news outlets. They then craft tailored spear‑phishing emails that impersonate trusted Korean vendors or agencies, often embedding malicious LNK files, Office documents (DOC, HWP, CHM) or QR codes that direct victims to compromised blogs. Once a target opens the attachment, Kimsuky unloads a modular backdoor such as AppleSeed, xRAT or RftRAT. The malware establishes persistence via PowerShell scripts or legitimate‑looking service entries, enumerates the system and exfiltrates data through covert channels (mail protocols, HTTPS, cloud storage). Keylogging tools like KLogEXE and FPSpy are distributed to harvest credentials and input data, while the group leverages encrypted archives, XOR payloads and signed binaries with genuine certificates to evade heuristic detection. In 2023 and 2024, Kimsuky began using commercial large language models (LLMs) to accelerate target analysis and social‑engineering content generation—identifying high‑value individuals and drafting personalized spear‑phishing messages. The adversary’s infrastructure is distributed across malicious websites, compromised domains such as "webcamsdk-update.online," and cloud services, illustrating a move toward greater operational stealth and redundancy. Kimsuky’s campaigns have spanned several high‑profile incidents—Operation Stolen Pencil (2018) targeting global tech firms, Operation Kabar Cobra (2019) against nuclear policy research bodies, and the 2014 infiltration of Korea Hydro & Nuclear Power Co. The group continues to adapt its toolset with new RATs, keyloggers and Android malware variants in order to meet evolving defensive postures.

Goals & Targeting

Targeted Sectors

Government
Financial services
Energy
Think tank
Think tank
Defense
Education
Nuclear
Media
Pharmaceutical
Manufacturing
Healthcare
Non profit
Transportation
Critical infrastructure

Targeted Countries / Regions

KR
KP
US
JP
RU
CN
UA
PK

AI Analysis

Grounded in web research
· analyzed in 4 chunks · 2 days ago

Executive Summary

Kimsuky is a North‑Korean state-sponsored cyber espionage actor active since at least 2012, focused on gathering sensitive information from government entities, think‑tanks, academia and related organizations worldwide. The group deploys a sophisticated mix of spear‑phishing, social engineering, malicious documents and LNK files, coupled with RAT backdoors such as AppleSeed, xRAT, and RftRAT to achieve persistence and exfiltration. Recent activity shows Kimsuky expanding its tactics to include large language model assistance for target selection, Android malware campaigns, and the use of signed binaries and compromised websites to evade detection.

Goals & Targeting

Kimsuky’s strategic objective is state‑level intelligence gathering on issues critical to North Korean foreign policy—particularly those related to the Korean Peninsula, nuclear negotiations, sanctions enforcement, and security dynamics involving the US, Japan, Russia and European partners. The actor deliberately targets government ministries, defense establishments, research institutes, media houses, educational institutions and corporate vendors that produce or influence public discourse on these topics. By infiltrating these organizations, Kimsuky can obtain policy documents, internal communications, technical data on missile development and diplomatic correspondence, thereby enhancing the DPRK’s strategic decision‑making capabilities. The targeting profile is highly selective: individuals with direct policy influence (senior officials, analysts, academic experts) are prioritized, often through personalized spear‑phishing. Secondary targets include service providers and vendors that interact with primary victims, to widen the attack surface and provide additional access pathways.

Enhanced Description

Key Capabilities

  • Spear‑phishing campaigns with malicious LNK files
  • Social engineering tactics impersonating Korean entities
  • Delivery of malware via malicious document attachments (DOC, HWP, CHM)
  • Keylogging for data capture (KLogEXE, FPSpy)
  • Tailored backdoor variants (AppleSeed, xRAT, RftRAT)
  • Use of large language models to identify targets and craft social‑engineering content
  • Deployment through compromised blogs & websites
  • Android malware campaigns
  • Persistence via PowerShell scripts and legitimate service entries
  • Binary obfuscation using XOR, Base64 and DLL modifications
  • Signing binaries with valid certificates for evasion
  • LNK masquerades, PDFs with malicious links, QR code-based infection vectors

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Privilege Escalation
Persistence
Defense Evasion
Credential Access
Collection
Exfiltration

ATT&CK Techniques

T1566.001
T1566.002
T1056.001
T1056.004
T1189
T1021
T1036
T1105
T1070.006
T1114
T1557
T1543.003
T1543
T1598.003
T1596
T1082
T1071
T1059.005
T1059.001
T1040
T1064
T1113
T1115
T1124
T1132
T1156
T1485
T1567.002

Software / Tooling

BabyShark
AppleSeed
AppleSeed backdoor
xRAT (Quasar RAT‑based)
RftRAT
Amadey
AutoIt
KGH_SPY
CSPY Downloader
KLogEXE
FPSpy

Campaigns & Victims

Kimsuky’s historical campaigns reveal an iterative improvement cycle, starting with targeting domestic Korean government and research entities before expanding globally to the US, Japan, Russia, Europe and beyond. Operations are often named (e.g., Stolen Pencil, Kabar Cobra, Smoke Screen) and involve a combination of spear‑phishing, compromised websites, keylogging, and RAT persistence. The actor’s tempo demonstrates consistent activity with significant bursts in 2018–2020 and again from 2023 onward, suggesting sustained operational capacity. Victim types include high‑profile government ministries, think‑tanks, defense contractors, media outlets and academic institutions, with a particular focus on subjects tied to nuclear policy and sanctions. Notably, Kimsuky has shown willingness to collaborate or share resources with other DPRK groups (Lazarus) as part of joint campaigns. In recent years, the group shifted toward utilizing LLMs for reconnaissance and attack‑package customization, indicating an investment in automation tools that reduce human effort while increasing precision. The use of mobile malware and signed binaries demonstrates a diversification of exploitation vectors beyond traditional Windows targets.

IOC Patterns

  • Malicious LNK files
  • Compromised websites as dropper sites
  • Spearphishing URLs and attachments (DOC/HWP/CHM/PDF)
  • Keylogger binaries (KLogEXE, FPSpy)
  • RAT backdoor installers (AppleSeed, xRAT, RftRAT)
  • Android malware campaigns
  • Signed malicious binaries using legitimate certificates
  • QR‑code based infection vectors
  • Domain indicators (e.g., coalink.support, webcamsdk-update.online)
  • IP indicators (e.g., 144.172.110.53, 88.119.171.59)

Recommended Actions

  • Deploy advanced email filtering with attachment sandboxing and malicious LNK detection
  • Integrate endpoint detection and response (EDR) focused on keylogging activity and PowerShell anomalies
  • Segment corporate networks to isolate high‑value assets and enforce least privilege
  • Monitor for unusual data staging and exfiltration patterns, especially via HTTPS/SSO Enforce multi‑factor authentication for all privileged accounts and restrict use of remote desktop protocols Maintain up‑to‑date threat intelligence feeds on Kimsuky variants, malware hashes and malicious domains
  • Block or quarantine known malicious domains/IPs identified by the threat community

Suggested Tags

North Korea
APT43
Black Banshee
Velvet Chollima
Emerald Sleet
Sparkling Pisces
Kimsuky
Cyber espionage
Government targeting
Think tanks
Media organizations
Social engineering
Spear‑phishing
Malicious LNK
Keylogger
Android malware
Downloader
Reconnaissance

Confidence Assessment

The information assembled is derived from multiple reputable public sources, including Security Labs, CISA advisories, and vendor threat reports. These provide a relatively confident understanding of Kimsuky’s objectives, targeting profile and known capabilities. However, attribution remains inherently uncertain due to the covert nature of nation‑state actors; some technical details are inferred or based on observed behaviors rather than confirmed source code analysis. Gaps exist in precise timelines for first/last seen activity, full scope of infrastructure (including domain registration data) and details on any internal collaboration with other DPRK groups.

ATT&CK Techniques

Collection
15 techniques
Command & Control
11 techniques
Credential Access
9 techniques
Defense impairment
4 techniques
Discovery
11 techniques
Execution
12 techniques
Initial Access
5 techniques
Persistence
11 techniques
Reconnaissance
11 techniques
Resource Development
17 techniques
Stealth
34 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 15 Filename 3 SHA-1 Hash 2

References

  1. Cloudflare 2026 Threat Report New Threat Actors March 2026 — Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
  2. AhnLab Kimsuky Kabar Cobra Feb 2019 — AhnLab. (2019, February 28). Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group. Retrieved September 29, 2021.
  3. EST Kimsuky April 2019 — Alyac. (2019, April 3). Kimsuky Organization Steals Operation Stealth Power. Retrieved August 13, 2019.
  4. Netscout Stolen Pencil Dec 2018 — ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.
  5. Zdnet Kimsuky Dec 2018 — Cimpanu, C.. (2018, December 5). Cyber-espionage group uses Chrome extension to infect victims. Retrieved August 26, 2019.
  6. CISA AA20-301A Kimsuky — CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.
  7. Cybereason Kimsuky November 2020 — Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.
  8. EST Kimsuky SmokeScreen April 2019 — ESTSecurity. (2019, April 17). Analysis of the APT Campaign ‘Smoke Screen’ targeting to Korea and US 출처: https://blog.alyac.co.kr/2243 [이스트시큐리티 알약 블로그]. Retrieved September 29, 2021.
  9. Malwarebytes Kimsuky June 2021 — Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.
  10. Proofpoint TA427 April 2024 — Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024.
  11. Mandiant APT43 March 2024 — Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.
  12. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  13. MSFT-AI — Microsoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. Retrieved March 11, 2024.
  14. Rapid7 Threat Landscape Actors March 2026 — Rapid7. (2026, March 18). 2026 GLOBAL THREAT LANDSCAPE REPORT: Decoding the Accelerated Cyber Attack Cycle. Retrieved April 18, 2026.
  15. Symantec Troll Stealer 2024 — Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.
  16. Securelist Kimsuky Sept 2013 — Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.
  17. ThreatConnect Kimsuky September 2020 — ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020.
  18. apt.etda.or.th — Cited by web research for: PowerShell
  19. www.huntress.com — Cited by web research for: LNK files
  20. attack.mitre.org — Cited by web research for: QuasarRAT
  21. www.sentinelone.com — Cited by web research for: rfa.ink
  22. unit42.paloaltonetworks.com — Cited by web research for: include.php
  23. www.cybereason.com — Cited by web research for: Pharmaceutical
  24. https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3413621/us-rok-agencies-alert-dp — Cited by AI analysis.
  25. https://therecord.media/kimsuky-north-korea-espionage-groupware-companies — Cited by AI analysis.
  26. https://twitter.com/issuemakerslab/status/1233010155018604545 — Cited by AI analysis.
  27. https://securelist.com/apt-trends-report-q1-2021/101967/ — Cited by AI analysis.
  28. https://blog.talosintelligence.com/2021/11/kimsuky-abuses-blogs-delivers-malware.html — Cited by AI analysis.
  29. https://asec.ahnlab.com/en/31089/ — Cited by AI analysis.
  30. https://medium.com/s2wblog/unveil-the-evolution-of-kimsuky-targeting-android-devices-with-newly-discovered-mobile-malware-280dae5a650f — Cited by AI analysis.
  31. https://asec.ahnlab.com/en/49295/ — Cited by AI analysis.
  32. https://therecord.media/north-korea-apt-kimsuky-attacks — Cited by AI analysis.
  33. https://asec.ahnlab.com/en/50303/ — Cited by AI analysis.
  34. https://asec.ahnlab.com/en/54678/ — Cited by AI analysis.
  35. https://asec.ahnlab.com/en/52970/ — Cited by AI analysis.
  36. https://www.sentinelone.com/labs/kimsuky-new-social-engineering-campaign-aims-to-steal-credentials-and-gather-strategic-intelligence/ — Cited by AI analysis.
  37. https://media.defense.gov/2023/Jun/01/2003234055/-1/-1/0/JOINT_CSA_DPRK_SOCIAL_ENGINEERING.PDF — Cited by AI analysis.
  38. https://asec.ahnlab.com/en/54736/ — Cited by AI analysis.
  39. https://asec.ahnlab.com/en/59387/ — Cited by AI analysis.
  40. https://asec.ahnlab.com/en/66546/ — Cited by AI analysis.
  41. https://asec.ahnlab.com/en/59590/ — Cited by AI analysis.

Intel Summary

155

Techniques

58

Tools

0

Campaigns

228

IOCs

0

Observed Data

16

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
espionage
North Korea
state-sponsored
government
defense
think tank
AI‑assisted
spear‑phishing
APT43
Black Banshee
Velvet Chollima
Emerald Sleet
Sparkling Pisces
Kimsuky
Cyber espionage
Government targeting
Think tanks
Media organizations
Social engineering
Spear‑phishing
Malicious LNK
Keylogger
Android malware
Downloader
Reconnaissance

Details

MITRE ID
G0094
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
North Korea (KP)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--0ec2f388-bf0f-4b5c-97b1-fc736d26c25f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.