BabyShark

MITRE ATT&CK: S0414 View on attack.mitre.org

Aliases: LATEOP, BabyShark

Malware type
spyware
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:41:37

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:kr

Context

BabyShark is a Microsoft Visual Basic (VB) script-based malware family that is believed to be associated with several North Korean campaigns.

Detection coverage

  • 1 YARA rules
  • 329 Sigma rules

Malware & tools used

  • Scheduled Task (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Query Registry (attack-pattern)
  • Mshta (attack-pattern)
  • Keylogging (attack-pattern)
  • Process Discovery (attack-pattern)
  • Visual Basic (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • File Deletion (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Babyshark_Auto (yara-rule)

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 2 (report)
  • bloomberglaw.com — X67Fpndoubv9Vops35A4864Bfiu (report)
  • Palo Alto Unit 42 — New Babyshark Malware Targets U S National Security Think Tanks (report)
  • CISA — Aa20 301A (report)
  • cybereason.com — Back To The Future Inside The Kimsuky Kgh Spyware Suite (report)
  • services.google.com — Apt43 Report En (report)
  • github.com — Microsoft 365 Defender Hunting Queries (report)
  • youtube.com — Watch (report)
  • genians.co.kr — Triple Combo (report)
  • i.blackhat.com — As 21 Kuo We Are About To Land How Clouddragon Turns A Nightmare Into Reality (report)
  • conference.hitb.org — D2T1%20 %20The%20Phishermen%20 %20Dissecting%20Phishing%20Techniques%20Of%20Clouddragon%20Apt%20 %20Linda%20Kuo%20&Zih Cing%20Liao%20 (report)
  • youtube.com — Watch (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Babyshark (report)
  • blog.google — How Were Protecting Users From Government Backed Attacks From North Korea (report)
  • sentinelone.com — Kimsuky Evolves Reconnaissance Capabilities In New Global Campaign (report)
  • huntress.com — Targeted Apt Activity Babyshark Is Out For Blood (report)
  • pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 1 (report)
  • blog.alyac.co.kr — 3352 (report)
  • twitter.com — 1099147896950185985 (report)
  • pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 2 (report)
  • kroll.com — Screenconnect Vulnerability Exploited To Deploy Babyshark (report)
  • MITRE ATT&CK — S0414 (report)
  • Palo Alto Unit 42 — Babyshark Malware Part Two Attacks Continue Using Kimjongrat And Pcrat (report)

External references