FORENSIA

THREAT_ACTOR · G0094

Kimsuky

Also known as: Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug

Profile

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

MITRE ATT&CK ↗

Techniques

130 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1005 Data from Local SystemT1007 System Service DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1020 Automated ExfiltrationT1021.001 Remote Desktop ProtocolT1027 Obfuscated Files or InformationT1027.001 Binary PaddingT1027.002 Software PackingT1027.007 Dynamic API ResolutionT1027.010 Command ObfuscationT1027.012 LNK Icon SmugglingT1027.013 Encrypted/Encoded FileT1027.015 CompressionT1027.016 Junk Code InsertionT1033 System Owner/User DiscoveryT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1036.007 Double File ExtensionT1040 Network SniffingT1041 Exfiltration Over C2 ChannelT1053.005 Scheduled TaskT1055 Process InjectionT1055.001 Dynamic-link Library InjectionT1055.012 Process HollowingT1056.001 KeyloggingT1056.003 Web Portal CaptureT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.006 PythonT1059.007 JavaScriptT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1071.002 File Transfer ProtocolsT1071.003 Mail ProtocolsT1074.001 Local Data StagingT1078.003 Local AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1098.007 Additional Local or Domain GroupsT1102.001 Dead Drop ResolverT1102.002 Bidirectional CommunicationT1105 Ingress Tool TransferT1106 Native APIT1111 Multi-Factor Authentication InterceptionT1112 Modify RegistryT1113 Screen CaptureT1114.002 Remote Email CollectionT1114.003 Email Forwarding RuleT1115 Clipboard DataT1124 System Time DiscoveryT1132.002 Non-Standard EncodingT1133 External Remote ServicesT1136.001 Local AccountT1140 Deobfuscate/Decode Files or InformationT1176.001 Browser ExtensionsT1185 Browser Session HijackingT1190 Exploit Public-Facing ApplicationT1204.001 Malicious LinkT1204.002 Malicious FileT1204.004 Malicious Copy and PasteT1205 Traffic SignalingT1217 Browser Information DiscoveryT1218.005 MshtaT1218.010 Regsvr32T1218.011 Rundll32T1219.002 Remote Desktop SoftwareT1480.002 Mutual ExclusionT1489 Service StopT1497.001 System ChecksT1505.003 Web ShellT1518.001 Security Software DiscoveryT1534 Internal SpearphishingT1539 Steal Web Session CookieT1543.003 Windows ServiceT1546.001 Change Default File AssociationT1547.001 Registry Run Keys / Startup FolderT1550.002 Pass the HashT1552.001 Credentials In FilesT1552.004 Private KeysT1553.002 Code SigningT1555.003 Credentials from Web BrowsersT1557 Adversary-in-the-MiddleT1559.001 Component Object ModelT1560.001 Archive via UtilityT1560.003 Archive via Custom MethodT1564.002 Hidden UsersT1564.003 Hidden WindowT1564.011 Ignore Process InterruptsT1566 PhishingT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1567.002 Exfiltration to Cloud StorageT1568 Dynamic ResolutionT1583 Acquire InfrastructureT1583.001 DomainsT1583.004 ServerT1583.006 Web ServicesT1584.001 DomainsT1585 Establish AccountsT1585.001 Social Media AccountsT1585.002 Email AccountsT1586.002 Email AccountsT1587 Develop CapabilitiesT1587.001 MalwareT1588.002 ToolT1588.003 Code Signing CertificatesT1588.005 ExploitsT1589.002 Email AddressesT1589.003 Employee NamesT1591 Gather Victim Org InformationT1593.001 Social MediaT1593.002 Search EnginesT1594 Search Victim-Owned WebsitesT1596 Search Open Technical DatabasesT1598 Phishing for InformationT1598.003 Spearphishing LinkT1608.001 Upload MalwareT1620 Reflective Code LoadingT1657 Financial TheftT1678 Delay ExecutionT1680 Local Storage DiscoveryT1682 Query Public AI ServicesT1684.001 ImpersonationT1685 Disable or Modify ToolsT1686 Disable or Modify System Firewall

Software

19 malware/tools attributed to this actor.

MimikatzPsExecgh0st RATschtaskscertutilGold DragonBrave PrinceQuasarRATNOKKIBabySharkKGH_SPYCSPY DownloaderAppleSeedAmadeyTroll StealerGoBearGomirTRANSLATEXTHTTPTroy

Related corpus activity

10,467 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Kimsuky.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-2492cve852
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-17456cve851
cve-2020-22658cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2025-23304cve852
cve-2021-4045cve851
cve-2020-22653cve852
cve-2022-47945cve851
cve-2025-34117cve851
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,467.