Kimsuky

MITRE ATT&CK: G0094 View on attack.mitre.org

Aliases: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Kimsuky, RGB-D5, Greendinosa

First seen
2012-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
1044 (820 malicious)
Last IoC activity
2026-09-02 00:39:39
Profile updated
2026-07-07 11:53:46

Targeted industries: government-and-public-sector education-and-nonprofits professional-services manufacturing energy-and-utilities

Targeted regions: country_code:kr country_code:us country_code:jp country_code:ru

Context

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

Recent IoC activity

821 malicious indicators in Maltiverse are attributed to Kimsuky (G0094). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname ndoc.nauthorize.r-e.kr 2026-09-03 1
hostname firmenakademie.com 2026-09-03 2
hostname www.k-admin-portal.quest 2026-09-03 1
hostname nid.naver.desaindigital.com 2026-09-03 2
hostname secure-cps.nl 2026-09-03 1
hostname www.digital-post.live 2026-09-03 1
hostname nchosedirect.maincert.1cooldns.com 2026-09-03 2
hostname nchosedirect.nooeg.1cooldns.com 2026-09-03 2
hostname www.e-billing-service.autos 2026-09-03 1
hostname nid.puoios.o-r.kr 2026-09-03 2
hostname kr-edoc.xubi.org 2026-09-03 1
hostname ndoc.niduser.1cooldns.com 2026-09-03 1
hostname korbit.work.gd 2026-09-03 2
hostname mois-auth-log.ttl.ydns.eu 2026-09-03 1
hostname www.maincert.1cooldns.com 2026-09-03 1
hostname nuser-login.nhl2vc.dynu.org 2026-09-03 2
hostname nid.naver.casepractice.com 2026-09-03 2
hostname xn--220b630b.xn--pz2bq8r.mois-viewer.o-r.kr 2026-09-03 1
hostname hgfhfj.ddnsfree.com 2026-09-03 1
hostname nid.kr-edoc.xubi.org 2026-09-03 1

Detection coverage

  • 28 YARA rules
  • 972 Sigma rules

Malware & tools used

  • Data from Local System (attack-pattern)
  • Malware (attack-pattern)
  • Acquire Infrastructure (attack-pattern)
  • Remote Desktop Protocol (attack-pattern)
  • Email Accounts (attack-pattern)
  • Phishing (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Malicious File (attack-pattern)
  • Network Sniffing (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Web Portal Capture (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Tool (attack-pattern)
  • Local Accounts (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Malicious Copy and Paste (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Upload Malware (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Develop Capabilities (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Phishing for Information (attack-pattern)
  • Impersonation (attack-pattern)
  • Code Signing (attack-pattern)

Related threat objects

Reports & references

  • Kaspersky — 57915 (report)
  • CISA — Aa20 301A (report)
  • cybereason.com — Back To The Future Inside The Kimsuky Kgh Spyware Suite (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • blog.cloudflare.com — 2026 Threat Report (report)
  • asert.arbornetworks.com — Stolen Pencil Campaign Targets Academia (report)
  • MITRE ATT&CK — G0094 (report)
  • blog.alyac.co.kr — 2234 (report)
  • blog.alyac.co.kr — Cfile5.Uf@99A0Cd415Cb67E210Dceb3 (report)
  • blog.malwarebytes.com — Kimsuky Apt Continues To Target South Korean Government Using Appleseed Backdoor (report)
  • global.ahnlab.com — %5Banalysis Report%5Doperation%20Kabar%20Cobra (report)
  • services.google.com — Apt43 Report En (report)
  • threatconnect.com — Kimsuky Phishing Operations Putting In Work (report)
  • Microsoft — Staying Ahead Of Threat Actors In The Age Of Ai (report)
  • proofpoint.com — Social Engineering Dmarc Abuse Ta427S Art Information Gathering (report)
  • rapid7.com — Rapid7 Threat Landscape Report 2026 (report)
  • security.com — Springtail Kimsuky Backdoor Espionage (report)
  • zdnet.com — Cyber Espionage Group Uses Chrome Extension To Infect Victims (report)

External references