Kimsuky
- First seen
- 2013-01-01 00:00:00
- Malware type
- spyware, backdoor
- Family
- Malware family
- Last IoC activity
- 2026-07-22 03:51:01
- Profile updated
- 2026-07-07 13:48:46
Targeted industries: government-and-public-sector education-and-nonprofits media-and-entertainment
Targeted regions: country_code:kr country_code:us
Context
Kimsuky is a cyber espionage group known to target South Korean entities, particularly in the government and media sectors. It is associated with the installation of spyware and backdoor tools to exfiltrate sensitive information.
Detection coverage
- 25 YARA rules
Used by threat actors
- Kimsuky Remote Desktop Access Activity (campaign)
Detection rules
- ARKBIRD_SOLG_APT_Kimsuky_Aug_2020_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Kimsuky (yara-rule)
- SEKOIA_Apt_Kimsuky_Vbs_Powershell_Downloader (yara-rule)
- SEKOIA_Kimsuky_Konni_Dll (yara-rule)
- SEKOIA_Apt_Kimsuky_Klogexe (yara-rule)
- SEKOIA_Apt_Kimsuky_Sharpext_Jsexfil_Strings (yara-rule)
- SEKOIA_Backoor_Win_Gobear (yara-rule)
- SEKOIA_Apt_Kimsuky_Sharptongue_Strings (yara-rule)
- SEKOIA_Apt_Kimsuky_Fpspy (yara-rule)
- SEKOIA_Apt_Kimsuky_Powershell_Dropper_Strings (yara-rule)
- SEKOIA_Apt_Kimsuky_Sharptongue_C2_Source (yara-rule)
- SEKOIA_Apt_Kimsuky_Toddlershark_Obfuscated (yara-rule)
- SEKOIA_Apt_Kimsuky_Malicious_Gotopwsh_Lnk (yara-rule)
- SEKOIA_Apt_Kimsuky_Sharpext_Devtoolmodule_Strings (yara-rule)
- SEKOIA_Apt_Kimsuky_Vbs (yara-rule)
- SEKOIA_Downloader_Kimsuky_Lnk (yara-rule)
- SEKOIA_Apt_Kimsuky_Toddlershark_Strings (yara-rule)
- SEKOIA_Apt_Kimsuky_Sharptongue_Vbslauncher_Strings (yara-rule)
- SEKOIA_Apt_Kimsuky_Validator_Strings (yara-rule)
- SEKOIA_Apt_Kimsuky_Malicious_Vba (yara-rule)
- SEKOIA_Rat_Win_Xeno_Rat (yara-rule)
- SEKOIA_Apt_Kimsuky_Powershell (yara-rule)
- SEKOIA_Apt_Kimsuky_Sharpext_Compromised_Securepreferences (yara-rule)
- SEKOIA_Backdoor_Win_Kimsuky (yara-rule)
- MALPEDIA_Win_Kimsuky_Auto (yara-rule)
Related threat objects
- Kimsuky (threat-actor)
Reports & references
- threatconnect.com — Threatconnect Research Roundup Probable Sandworm Infrastructure (report)
- blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
- cocomelonc.github.io — Malware Pers 1 (report)
- vblocalhost.com — Operation Newton Hi Kimsuky Did An Appleseed Really Fall On Newtons Head (report)
- asec.ahnlab.com — 30532 (report)
- boho.or.kr — Filedownload.Do (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Kimsuky (report)
- asec.ahnlab.com — 37396 (report)
- inquest.net — Kimsuky Espionage Campaign (report)
- virusbulletin.com — Vb2019 Kim (report)
- cocomelonc.github.io — Malware Pers 9 (report)
- virusbulletin.com — Vb2019 Paper Kimsuky Group Tracking King Spearphishing (report)
- web.archive.org — Autumn Aperture Report (report)
- asec.ahnlab.com — 53046 (report)
- blog.prevailion.com — Autumn Aperture Report (report)
- metaswan.github.io — Malware Kimsuky Group'S Resume Impersonation Malware (report)
- medium.com — Pivoting On A Sharpext To Profile Kimusky Panels For Great Good 1920Dc1Bcef9 (report)
- pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 1 (report)
- blog.alyac.co.kr — 2347 (report)
- hunt.io — Million Ok Naver Facade Kimsuky Tracking (report)
- threatmon.io — Unraveling The Layers Analysis Of Kimsukys Multi Staged Cyberattack (report)
- aryaka.com — Aryaka Kimsuky Apt Operational Blueprint (report)