Kimsuky
Also tracked as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.
- Documented techniques
- 130
- Assessed origin
- North Korea
- Assessed motivation
- Espionage
- First seen
- 2012
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance10
resource development15
- T1583 Acquire Infrastructure
- T1583.001 Domains
- T1583.004 Server
- T1583.006 Web Services
- T1584.001 Domains
- T1585 Establish Accounts
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1586.002 Email Accounts
- T1587 Develop Capabilities
- T1587.001 Malware
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1588.005 Exploits
- T1608.001 Upload Malware
initial access4
execution11
persistence7
privilege escalation1
credential access8
discovery11
- T1007 System Service Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1033 System Owner/User Discovery
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1124 System Time Discovery
- T1217 Browser Information Discovery
- T1518.001 Security Software Discovery
- T1680 Local Storage Discovery
lateral movement3
collection11
- T1005 Data from Local System
- T1056.001 Keylogging
- T1056.003 Web Portal Capture
- T1074.001 Local Data Staging
- T1113 Screen Capture
- T1114.002 Remote Email Collection
- T1114.003 Email Forwarding Rule
- T1115 Clipboard Data
- T1185 Browser Session Hijacking
- T1560.001 Archive via Utility
- T1560.003 Archive via Custom Method
command and control9
exfiltration3
defense impairment4
stealth31
- T1027 Obfuscated Files or Information
- T1027.001 Binary Padding
- T1027.002 Software Packing
- T1027.007 Dynamic API Resolution
- T1027.010 Command Obfuscation
- T1027.012 LNK Icon Smuggling
- T1027.013 Encrypted/Encoded File
- T1027.015 Compression
- T1027.016 Junk Code Insertion
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1036.007 Double File Extension
- T1055 Process Injection
- T1055.001 Dynamic-link Library Injection
- T1055.012 Process Hollowing
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1078.003 Local Accounts
- T1140 Deobfuscate/Decode Files or Information
- T1205 Traffic Signaling
- T1218.005 Mshta
- T1218.010 Regsvr32
- T1218.011 Rundll32
- T1480.002 Mutual Exclusion
- T1497.001 System Checks
- T1564.002 Hidden Users
- T1564.003 Hidden Window
- T1564.011 Ignore Process Interrupts
- T1620 Reflective Code Loading
- T1678 Delay Execution
- T1684.001 Impersonation
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.