Threat actor
Kimsuky
Last fetched
Kimsuky is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 130 techniques and also known as 13 other names.
Also known as
Velvet Chollima, Black Banshee, Thallium, Operation Stolen Pencil, G0086, APT43, Emerald Sleet, THALLIUM, Springtail, Sparkling Pisces, TA427, Earth Kumiho, PatheticSlug
Description
[Kimsuky](https://attack.mitre.org/groups/G0094) is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. [Kimsuky](https://attack.mitre.org/groups/G0094) has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. [Kimsuky](https://attack.mitre.org/groups/G0094) operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.(Citation: EST Kimsuky April 2019)(Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: CISA AA20-301A Kimsuky)(Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024) [Kimsuky](https://attack.mitre.org/groups/G0094) was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).(Citation: Netscout Stolen Pencil Dec 2018)(Citation: EST Kimsuky SmokeScreen April 2019)(Citation: AhnLab Kimsuky Kabar Cobra Feb 2019) In 2023, [Kimsuky](https://attack.mitre.org/groups/G0094) was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.(Citation: MSFT-AI) DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under [Lazarus Group](https://attack.mitre.org/groups/G0032), rather than tracking operationally distinct subgroups.
Techniques by tactic
Collection
- T1005 · Data from Local System
- T1056.001 · Keylogging
- T1056.003 · Web Portal Capture
- T1074.001 · Local Data Staging
- T1113 · Screen Capture
- T1114.002 · Remote Email Collection
- T1114.003 · Email Forwarding Rule
- T1115 · Clipboard Data
- T1185 · Browser Session Hijacking
- T1557 · Adversary-in-the-Middle
- T1560.001 · Archive via Utility
- T1560.003 · Archive via Custom Method
Command and Control
- T1071.001 · Web Protocols
- T1071.002 · File Transfer Protocols
- T1071.003 · Mail Protocols
- T1102.001 · Dead Drop Resolver
- T1102.002 · Bidirectional Communication
- T1105 · Ingress Tool Transfer
- T1132.002 · Non-Standard Encoding
- T1205 · Traffic Signaling
- T1219.002 · Remote Desktop Software
- T1568 · Dynamic Resolution
Credential Access
- T1003.001 · LSASS Memory
- T1040 · Network Sniffing
- T1056.001 · Keylogging
- T1056.003 · Web Portal Capture
- T1111 · Multi-Factor Authentication Interception
- T1539 · Steal Web Session Cookie
- T1552.001 · Credentials In Files
- T1552.004 · Private Keys
- T1555.003 · Credentials from Web Browsers
- T1557 · Adversary-in-the-Middle
Discovery
- T1007 · System Service Discovery
- T1012 · Query Registry
- T1016 · System Network Configuration Discovery
- T1033 · System Owner/User Discovery
- T1040 · Network Sniffing
- T1057 · Process Discovery
- T1082 · System Information Discovery
- T1083 · File and Directory Discovery
- T1124 · System Time Discovery
- T1217 · Browser Information Discovery
- T1497.001 · System Checks
- T1518.001 · Security Software Discovery
- T1680 · Local Storage Discovery
Persistence
- T1053.005 · Scheduled Task
- T1078.003 · Local Accounts
- T1098.007 · Additional Local or Domain Groups
- T1112 · Modify Registry
- T1133 · External Remote Services
- T1136.001 · Local Account
- T1176.001 · Browser Extensions
- T1205 · Traffic Signaling
- T1505.003 · Web Shell
- T1543.003 · Windows Service
- T1546.001 · Change Default File Association
- T1547.001 · Registry Run Keys / Startup Folder
Privilege Escalation
- T1053.005 · Scheduled Task
- T1055 · Process Injection
- T1055.001 · Dynamic-link Library Injection
- T1055.012 · Process Hollowing
- T1078.003 · Local Accounts
- T1098.007 · Additional Local or Domain Groups
- T1543.003 · Windows Service
- T1546.001 · Change Default File Association
- T1547.001 · Registry Run Keys / Startup Folder
Reconnaissance
- T1589.002 · Email Addresses
- T1589.003 · Employee Names
- T1591 · Gather Victim Org Information
- T1593.001 · Social Media
- T1593.002 · Search Engines
- T1594 · Search Victim-Owned Websites
- T1596 · Search Open Technical Databases
- T1598 · Phishing for Information
- T1598.003 · Spearphishing Link
- T1682 · Query Public AI Services
Resource Development
- T1583 · Acquire Infrastructure
- T1583.001 · Domains
- T1583.004 · Server
- T1583.006 · Web Services
- T1584.001 · Domains
- T1585 · Establish Accounts
- T1585.001 · Social Media Accounts
- T1585.002 · Email Accounts
- T1586.002 · Email Accounts
- T1587 · Develop Capabilities
- T1587.001 · Malware
- T1588.002 · Tool
- T1588.003 · Code Signing Certificates
- T1588.005 · Exploits
- T1608.001 · Upload Malware
Stealth
- T1027 · Obfuscated Files or Information
- T1027.001 · Binary Padding
- T1027.002 · Software Packing
- T1027.007 · Dynamic API Resolution
- T1027.010 · Command Obfuscation
- T1027.012 · LNK Icon Smuggling
- T1027.013 · Encrypted/Encoded File
- T1027.015 · Compression
- T1027.016 · Junk Code Insertion
- T1036.004 · Masquerade Task or Service
- T1036.005 · Match Legitimate Resource Name or Location
- T1036.007 · Double File Extension
- T1055 · Process Injection
- T1055.001 · Dynamic-link Library Injection
- T1055.012 · Process Hollowing
- T1070.004 · File Deletion
- T1070.006 · Timestomp
- T1078.003 · Local Accounts
- T1140 · Deobfuscate/Decode Files or Information
- T1205 · Traffic Signaling
- T1218.005 · Mshta
- T1218.010 · Regsvr32
- T1218.011 · Rundll32
- T1480.002 · Mutual Exclusion
- T1497.001 · System Checks
- T1564.002 · Hidden Users
- T1564.003 · Hidden Window
- T1564.011 · Ignore Process Interrupts
- T1620 · Reflective Code Loading
- T1678 · Delay Execution
- T1684.001 · Impersonation
Attributed infrastructure
Infrastructure with a published ATTRIBUTED_TO link to Kimsuky in WhisperGraph. Attribution is sparse graph-wide — this list is rarely exhaustive.
- www.dolgicap.comHOSTNAME
- 27.102.138.44IPV4
References
- https://securelist.com/the-kimsuky-operation-a-north-korean-apt/57915/
- https://www.cfr.org/interactive/cyber-operations/kimsuky
- https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/tracking-kimsuky-north-korea-based-cyber-espionage-group-part-2.html
- https://youtu.be/hAsKp43AZmM?t=1027
- https://www.bloomberglaw.com/document/public/subdoc/X67FPNDOUBV9VOPS35A4864BFIU?imagename=1
- https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academia
- https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/
- https://attack.mitre.org/groups/G0086/
- https://us-cert.cisa.gov/ncas/alerts/aa20-301a
- https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite
- https://mandiant.widen.net/s/zvmfw5fnjs/apt43-report
- https://asec.ahnlab.com/en/57873/
- https://asec.ahnlab.com/en/61082/
- https://www.rewterz.com/rewterz-news/rewterz-threat-alert-north-korean-apt-kimsuky-aka-black-banshee-active-iocs-29/
- https://www.sentinelone.com/labs/a-glimpse-into-future-scarcruft-campaigns-attackers-gather-strategic-intelligence-and-target-cybersecurity-professionals/
- https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Cyber-Sicherheitslage/Analysen-und-Prognosen/Threat-Intelligence/Aktive_APT-Gruppen/aktive-apt-gruppen_node.html
- https://ctoatncsc.substack.com/p/cto-at-ncsc-summary-week-ending-may-16b
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/springtail-kimsuky-backdoor-espionage
- https://unit42.paloaltonetworks.com/kimsuky-new-keylogger-backdoor-variant/
- https://attack.mitre.org/groups/G0094
- https://blog.cloudflare.com/2026-threat-report/
- https://global.ahnlab.com/global/upload/download/techreport/%5BAnalysis_Report%5DOperation%20Kabar%20Cobra.pdf
- https://blog.alyac.co.kr/2234
- https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/
- https://www.zdnet.com/article/cyber-espionage-group-uses-chrome-extension-to-infect-victims/
- https://blog.alyac.co.kr/attachment/cfile5.uf@99A0CD415CB67E210DCEB3.pdf
- https://blog.malwarebytes.com/threat-analysis/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/
- https://www.proofpoint.com/us/blog/threat-insight/social-engineering-dmarc-abuse-ta427s-art-information-gathering
- https://services.google.com/fh/files/misc/apt43-report-en.pdf
- https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide
- https://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-age-of-ai/
- https://www.rapid7.com/cdn/assets/bltc1ddd6561ab54a26/69ba67de50ca691edcd3f5b7/rapid7-threat-landscape-report-2026.pdf
- https://www.security.com/threat-intelligence/springtail-kimsuky-backdoor-espionage
- https://threatconnect.com/blog/kimsuky-phishing-operations-putting-in-work/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Kimsuky into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.