Kimsuky
MITRE ATT&CK: G0094 View on attack.mitre.org
Aliases: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Kimsuky, RGB-D5, Greendinosa
- First seen
- 2012-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 1044 (820 malicious)
- Last IoC activity
- 2026-09-02 00:39:39
- Profile updated
- 2026-07-07 11:53:46
Targeted industries: government-and-public-sector education-and-nonprofits professional-services manufacturing energy-and-utilities
Targeted regions: country_code:kr country_code:us country_code:jp country_code:ru
Context
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.
Recent IoC activity
821 malicious indicators in Maltiverse are attributed to Kimsuky (G0094). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | ndoc.nauthorize.r-e.kr | 2026-09-03 | 1 |
| hostname | firmenakademie.com | 2026-09-03 | 2 |
| hostname | www.k-admin-portal.quest | 2026-09-03 | 1 |
| hostname | nid.naver.desaindigital.com | 2026-09-03 | 2 |
| hostname | secure-cps.nl | 2026-09-03 | 1 |
| hostname | www.digital-post.live | 2026-09-03 | 1 |
| hostname | nchosedirect.maincert.1cooldns.com | 2026-09-03 | 2 |
| hostname | nchosedirect.nooeg.1cooldns.com | 2026-09-03 | 2 |
| hostname | www.e-billing-service.autos | 2026-09-03 | 1 |
| hostname | nid.puoios.o-r.kr | 2026-09-03 | 2 |
| hostname | kr-edoc.xubi.org | 2026-09-03 | 1 |
| hostname | ndoc.niduser.1cooldns.com | 2026-09-03 | 1 |
| hostname | korbit.work.gd | 2026-09-03 | 2 |
| hostname | mois-auth-log.ttl.ydns.eu | 2026-09-03 | 1 |
| hostname | www.maincert.1cooldns.com | 2026-09-03 | 1 |
| hostname | nuser-login.nhl2vc.dynu.org | 2026-09-03 | 2 |
| hostname | nid.naver.casepractice.com | 2026-09-03 | 2 |
| hostname | xn--220b630b.xn--pz2bq8r.mois-viewer.o-r.kr | 2026-09-03 | 1 |
| hostname | hgfhfj.ddnsfree.com | 2026-09-03 | 1 |
| hostname | nid.kr-edoc.xubi.org | 2026-09-03 | 1 |
Detection coverage
- 28 YARA rules
- 972 Sigma rules
Malware & tools used
- Data from Local System (attack-pattern)
- Malware (attack-pattern)
- Acquire Infrastructure (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Email Accounts (attack-pattern)
- Phishing (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Malicious File (attack-pattern)
- Network Sniffing (attack-pattern)
- Spearphishing Link (attack-pattern)
- Web Portal Capture (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Tool (attack-pattern)
- Local Accounts (attack-pattern)
- Automated Exfiltration (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Malicious Copy and Paste (attack-pattern)
- Command Obfuscation (attack-pattern)
- Upload Malware (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Develop Capabilities (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Phishing for Information (attack-pattern)
- Impersonation (attack-pattern)
- Code Signing (attack-pattern)
Related threat objects
- Kimsuky (threat-actor)
Reports & references
- Kaspersky — 57915 (report)
- CISA — Aa20 301A (report)
- cybereason.com — Back To The Future Inside The Kimsuky Kgh Spyware Suite (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- blog.cloudflare.com — 2026 Threat Report (report)
- asert.arbornetworks.com — Stolen Pencil Campaign Targets Academia (report)
- MITRE ATT&CK — G0094 (report)
- blog.alyac.co.kr — 2234 (report)
- blog.alyac.co.kr — Cfile5.Uf@99A0Cd415Cb67E210Dceb3 (report)
- blog.malwarebytes.com — Kimsuky Apt Continues To Target South Korean Government Using Appleseed Backdoor (report)
- global.ahnlab.com — %5Banalysis Report%5Doperation%20Kabar%20Cobra (report)
- services.google.com — Apt43 Report En (report)
- threatconnect.com — Kimsuky Phishing Operations Putting In Work (report)
- Microsoft — Staying Ahead Of Threat Actors In The Age Of Ai (report)
- proofpoint.com — Social Engineering Dmarc Abuse Ta427S Art Information Gathering (report)
- rapid7.com — Rapid7 Threat Landscape Report 2026 (report)
- security.com — Springtail Kimsuky Backdoor Espionage (report)
- zdnet.com — Cyber Espionage Group Uses Chrome Extension To Infect Victims (report)
External references
- mitre-attack — G0094
- Cloudflare 2026 Threat Report New Threat Actors March 2026
- PatheticSlug
- Black Banshee
- THALLIUM
- APT43
- Emerald Sleet
- TA427
- Earth Kumiho
- Kimsuky
- Springtail
- Velvet Chollima
- AhnLab Kimsuky Kabar Cobra Feb 2019
- EST Kimsuky April 2019
- Netscout Stolen Pencil Dec 2018
- Zdnet Kimsuky Dec 2018
- CISA AA20-301A Kimsuky
- Cybereason Kimsuky November 2020
- EST Kimsuky SmokeScreen April 2019
- Malwarebytes Kimsuky June 2021