NEW: Group Profiler — instant APT intel lookup. Try it →

Kimsuky

G0094 North Korea Espionage MITRE ATT&CK →

Also known as: Black Banshee · Velvet Chollima · Emerald Sleet · THALLIUM · APT43 · TA427 · Springtail · Earth Kumiho · PatheticSlug

Overview

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

Naming & attribution

Kimsuky is tracked under 10 names across the industry. It uses 130 documented ATT&CK techniques — more than 99% of the 174 groups tracked here. Activity attributed since at least 2012.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
Black BansheeDahan, A. et al
Velvet ChollimaCimpanu, C.
Emerald SleetMicrosoft
THALLIUMDahan, A. et al
APT43Mandiant
TA427Lesnewich, G. et al
SpringtailSymantec Threat Hunter Team
Earth KumihoRapid7
PatheticSlugCloudflare
KimsukyTarakanov , D.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1132.002 Non-Standard Encoding — used by 1 of 174 groups
  • T1176.001 Browser Extensions — used by 1 of 174 groups
  • T1185 Browser Session Hijacking — used by 1 of 174 groups
  • T1546.001 Change Default File Association — used by 1 of 174 groups
  • T1593.002 Search Engines — used by 1 of 174 groups
  • T1036.007 Double File Extension — used by 2 of 174 groups
  • T1056.003 Web Portal Capture — used by 2 of 174 groups
  • T1480.002 Mutual Exclusion — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • Mustang Panda China — 48 shared techniques (29% overlap)
  • Gamaredon Group Russia — 45 shared techniques (29% overlap)
  • MuddyWater Iran — 44 shared techniques (29% overlap)
  • Lazarus Group North Korea — 49 shared techniques (28% overlap)
  • APT32 Vietnam — 45 shared techniques (28% overlap)
  • Magic Hound Iran — 45 shared techniques (28% overlap)

Malware families with current indicators

2 families attributed to Kimsuky, carrying 375 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Amadey 373 indicators
  • Appleseed 2 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Defense · Diplomacy · Education · Energy · Government · Media · Private sector · Research - Innovation

Regions

Germany · Korea Institute for Defense Analyses · Ministry of Unification · Sejong Institute

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 13 attributed custom malware families

TTPs — 130 techniques across 15 tactics

Resource Development

Execution

Privilege Escalation

Lateral Movement

Impact

Tools & malware (19)

Troll Stealer · HTTPTroy · schtasks · certutil · Amadey · GoBear · Brave Prince · CSPY Downloader · gh0st RAT · AppleSeed · Gomir · NOKKI · QuasarRAT · Gold Dragon · PsExec · KGH_SPY · Mimikatz · BabyShark · TRANSLATEXT

Reporting (3)