Kimsuky

First seen
2013-01-01 00:00:00
Malware type
spyware, backdoor
Family
Malware family
Last IoC activity
2026-07-22 03:51:01
Profile updated
2026-07-07 13:48:46

Targeted industries: government-and-public-sector education-and-nonprofits media-and-entertainment

Targeted regions: country_code:kr country_code:us

Context

Kimsuky is a cyber espionage group known to target South Korean entities, particularly in the government and media sectors. It is associated with the installation of spyware and backdoor tools to exfiltrate sensitive information.

Detection coverage

  • 25 YARA rules

Used by threat actors

  • Kimsuky Remote Desktop Access Activity (campaign)

Detection rules

  • ARKBIRD_SOLG_APT_Kimsuky_Aug_2020_1 (yara-rule)
  • DITEKSHEN_MALWARE_Win_Kimsuky (yara-rule)
  • SEKOIA_Apt_Kimsuky_Vbs_Powershell_Downloader (yara-rule)
  • SEKOIA_Kimsuky_Konni_Dll (yara-rule)
  • SEKOIA_Apt_Kimsuky_Klogexe (yara-rule)
  • SEKOIA_Apt_Kimsuky_Sharpext_Jsexfil_Strings (yara-rule)
  • SEKOIA_Backoor_Win_Gobear (yara-rule)
  • SEKOIA_Apt_Kimsuky_Sharptongue_Strings (yara-rule)
  • SEKOIA_Apt_Kimsuky_Fpspy (yara-rule)
  • SEKOIA_Apt_Kimsuky_Powershell_Dropper_Strings (yara-rule)
  • SEKOIA_Apt_Kimsuky_Sharptongue_C2_Source (yara-rule)
  • SEKOIA_Apt_Kimsuky_Toddlershark_Obfuscated (yara-rule)
  • SEKOIA_Apt_Kimsuky_Malicious_Gotopwsh_Lnk (yara-rule)
  • SEKOIA_Apt_Kimsuky_Sharpext_Devtoolmodule_Strings (yara-rule)
  • SEKOIA_Apt_Kimsuky_Vbs (yara-rule)
  • SEKOIA_Downloader_Kimsuky_Lnk (yara-rule)
  • SEKOIA_Apt_Kimsuky_Toddlershark_Strings (yara-rule)
  • SEKOIA_Apt_Kimsuky_Sharptongue_Vbslauncher_Strings (yara-rule)
  • SEKOIA_Apt_Kimsuky_Validator_Strings (yara-rule)
  • SEKOIA_Apt_Kimsuky_Malicious_Vba (yara-rule)
  • SEKOIA_Rat_Win_Xeno_Rat (yara-rule)
  • SEKOIA_Apt_Kimsuky_Powershell (yara-rule)
  • SEKOIA_Apt_Kimsuky_Sharpext_Compromised_Securepreferences (yara-rule)
  • SEKOIA_Backdoor_Win_Kimsuky (yara-rule)
  • MALPEDIA_Win_Kimsuky_Auto (yara-rule)

Related threat objects

Reports & references

  • threatconnect.com — Threatconnect Research Roundup Probable Sandworm Infrastructure (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • cocomelonc.github.io — Malware Pers 1 (report)
  • vblocalhost.com — Operation Newton Hi Kimsuky Did An Appleseed Really Fall On Newtons Head (report)
  • asec.ahnlab.com — 30532 (report)
  • boho.or.kr — Filedownload.Do (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Kimsuky (report)
  • asec.ahnlab.com — 37396 (report)
  • inquest.net — Kimsuky Espionage Campaign (report)
  • virusbulletin.com — Vb2019 Kim (report)
  • cocomelonc.github.io — Malware Pers 9 (report)
  • virusbulletin.com — Vb2019 Paper Kimsuky Group Tracking King Spearphishing (report)
  • web.archive.org — Autumn Aperture Report (report)
  • asec.ahnlab.com — 53046 (report)
  • blog.prevailion.com — Autumn Aperture Report (report)
  • metaswan.github.io — Malware Kimsuky Group'S Resume Impersonation Malware (report)
  • medium.com — Pivoting On A Sharpext To Profile Kimusky Panels For Great Good 1920Dc1Bcef9 (report)
  • pwc.co.uk — Tracking Kimsuky North Korea Based Cyber Espionage Group Part 1 (report)
  • blog.alyac.co.kr — 2347 (report)
  • hunt.io — Million Ok Naver Facade Kimsuky Tracking (report)
  • threatmon.io — Unraveling The Layers Analysis Of Kimsukys Multi Staged Cyberattack (report)
  • aryaka.com — Aryaka Kimsuky Apt Operational Blueprint (report)

External references