BabyShark
MITRE ATT&CK: S0414 View on attack.mitre.org
Aliases: LATEOP, BabyShark
- Malware type
- spyware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 12:41:37
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:kr
Context
BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean campaigns.
Detection coverage
- 1 YARA rules
- 329 Sigma rules
Malware & tools used
- Scheduled Task (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Query Registry (attack-pattern)
- Mshta (attack-pattern)
- Keylogging (attack-pattern)
- Process Discovery (attack-pattern)
- Visual Basic (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Information Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- File Deletion (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
Used by threat actors
Detection rules
- MALPEDIA_Win_Babyshark_Auto (yara-rule)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 2 (report)
- bloomberglaw.com — X67Fpndoubv9Vops35A4864Bfiu (report)
- Palo Alto Unit 42 — New Babyshark Malware Targets U S National Security Think Tanks (report)
- CISA — Aa20 301A (report)
- cybereason.com — Back To The Future Inside The Kimsuky Kgh Spyware Suite (report)
- services.google.com — Apt43 Report En (report)
- github.com — Microsoft 365 Defender Hunting Queries (report)
- youtube.com — Watch (report)
- genians.co.kr — Triple Combo (report)
- i.blackhat.com — As 21 Kuo We Are About To Land How Clouddragon Turns A Nightmare Into Reality (report)
- conference.hitb.org — D2T1%20 %20The%20Phishermen%20 %20Dissecting%20Phishing%20Techniques%20Of%20Clouddragon%20Apt%20 %20Linda%20Kuo%20&Zih Cing%20Liao%20 (report)
- youtube.com — Watch (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Babyshark (report)
- blog.google — How Were Protecting Users From Government Backed Attacks From North Korea (report)
- sentinelone.com — Kimsuky Evolves Reconnaissance Capabilities In New Global Campaign (report)
- huntress.com — Targeted Apt Activity Babyshark Is Out For Blood (report)
- pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 1 (report)
- blog.alyac.co.kr — 3352 (report)
- twitter.com — 1099147896950185985 (report)
- pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 2 (report)
- kroll.com — Screenconnect Vulnerability Exploited To Deploy Babyshark (report)
- MITRE ATT&CK — S0414 (report)
- Palo Alto Unit 42 — Babyshark Malware Part Two Attacks Continue Using Kimjongrat And Pcrat (report)