Kimsuky
Also tracked as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.
- Known attack methods
- 130
- Origin
- North Korea
- Motive
- Espionage
- First seen
- 2012
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 7 used
Resource Development
9 techniques · 7 used
Initial Access
11 techniques · 2 used
Execution
20 techniques · 5 used
Persistence
22 techniques · 7 used
Privilege Escalation
13 techniques · 1 used
Stealth
30 techniques · 14 used
Defense Impairment
18 techniques · 4 used
Credential Access
17 techniques · 7 used
Discovery
34 techniques · 11 used
Lateral Movement
9 techniques · 3 used
Collection
17 techniques · 8 used
Command and Control
18 techniques · 6 used
Exfiltration
9 techniques · 3 used
Impact
15 techniques · 2 used
Reconnaissance10
Resource development15
- T1583Acquire Infrastructure
- T1583.001Domains
- T1583.004Server
- T1583.006Web Services
- T1584.001Domains
- T1585Establish Accounts
- T1585.001Social Media Accounts
- T1585.002Email Accounts
- T1586.002Email Accounts
- T1587Develop Capabilities
- T1587.001Malware
- T1588.002Tool
- T1588.003Code Signing Certificates
- T1588.005Exploits
- T1608.001Upload Malware
Initial access4
Execution11
Persistence7
Privilege escalation1
Stealth31
- T1027Obfuscated Files or Information
- T1027.001Binary Padding
- T1027.002Software Packing
- T1027.007Dynamic API Resolution
- T1027.010Command Obfuscation
- T1027.012LNK Icon Smuggling
- T1027.013Encrypted/Encoded File
- T1027.015Compression
- T1027.016Junk Code Insertion
- T1036.004Masquerade Task or Service
- T1036.005Match Legitimate Resource Name or Location
- T1036.007Double File Extension
- T1055Process Injection
- T1055.001Dynamic-link Library Injection
- T1055.012Process Hollowing
- T1070.004File Deletion
- T1070.006Timestomp
- T1078.003Local Accounts
- T1140Deobfuscate/Decode Files or Information
- T1205Traffic Signaling
- T1218.005Mshta
- T1218.010Regsvr32
- T1218.011Rundll32
- T1480.002Mutual Exclusion
- T1497.001System Checks
- T1564.002Hidden Users
- T1564.003Hidden Window
- T1564.011Ignore Process Interrupts
- T1620Reflective Code Loading
- T1678Delay Execution
- T1684.001Impersonation
Defense impairment4
Credential access8
Discovery11
- T1007System Service Discovery
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1033System Owner/User Discovery
- T1057Process Discovery
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1124System Time Discovery
- T1217Browser Information Discovery
- T1518.001Security Software Discovery
- T1680Local Storage Discovery
Collection11
Command and control9
Exfiltration3
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.