Kimsuky is a North Korea-aligned cyber espionage threat actor focused primarily on intelligence collection in support of DPRK strategic interests. The group is widely tracked under numerous aliases including APT43, Emerald Sleet, Opal Sleet, Velvet Chollima, TA406, Thallium, Black Banshee, Cerium, Springtail, SharpTongue, Osmium, Sparkling Pisces, and Ruby Sleet. Reporting has also associated the name Konni with overlapping or related DPRK activity in some contexts, though Kimsuky and Konni are often tracked separately by vendors. Kimsuky has consistently targeted government entities, diplomats, defense organizations, think tanks, academics, policy specialists, public-sector personnel, cryptocurrency-related targets, developers, and other individuals or organizations of intelligence value, with a strong emphasis on South Korea and other geopolitically relevant regions. The group is known for highly tailored spearphishing using topical lures such as policy documents, resumes, business correspondence, conference invitations, security notices, and government or institutional themes. It has also used QR-code phishing to redirect victims to mobile-optimized credential-harvesting pages and to support Android malware delivery. Operationally, Kimsuky relies heavily on social engineering, script-based malware chains, and living-off-the-land execution. Observed initial access vectors include malicious LNK files, ZIP archives, JSE and VBE scripts, and phishing pages impersonating trusted services. Campaigns commonly display decoy documents while silently dropping payloads, collecting host information, and establishing persistence. The group has used PowerShell extensively for staging, deobfuscation, reconnaissance, command execution, and payload retrieval, and has also used rundll32, regsvr32, WMI, scheduled tasks, and startup-folder shortcuts to maintain access and blend with normal administration. The actor frequently abuses legitimate platforms and cloud services for delivery, command and control, and evasion. Observed infrastructure patterns include use of GitHub raw content and GitHub Releases, Dropbox API, Google Drive, Microsoft-hosted content delivery infrastructure, and VS Code tunnel functionality. This tradecraft reduces reliance on obviously malicious infrastructure and complicates reputation-based blocking and network triage. Kimsuky malware and tooling have included remote access trojans and loaders delivered through multi-stage script chains, including campaigns involving HttpSpy variants and PowerShell-based RAT functionality. Capabilities observed across campaigns include system and environment reconnaissance, antivirus discovery, registry enumeration, credential theft, command execution, file upload and download, screenshot capture, remote DLL injection, and selective victim profiling based on identifiers such as IP address, MAC address, or host-specific values. The group commonly establishes persistence through scheduled tasks, Registry Run or RunOnce modifications, and Startup folder artifacts. It has also been observed querying specific Registry keys and values on compromised hosts and checking for installed antivirus products through PowerShell and WMI/CIM interfaces. Defensive evasion has included script obfuscation, use of legitimate binaries, anti-analysis checks, cleanup of staging artifacts, and selective payload delivery only to intended victims. Kimsuky remains one of the most active DPRK espionage operators and is notable for rapidly adapting lure themes and delivery mechanisms while preserving a consistent intrusion model centered on credential theft, long-term access, and intelligence collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
54 malware families attributed to this actor across reporting.
49 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
APT28 has used a variety of public exploits, including CVE 2020-0688 ... to gain execution on vulnerable Microsoft Exchange... Dragonfly ... exploited ... CVE-2020-0688 for ... MS Exchange... Kimsuky ... including Microsoft Exchange vulnerability CVE-2020-0688. MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
DPRK aligned TA406 (Opal Sleet) chained CVE-2026-21510 with CVE-2026-21509 in active campaigns.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
1,612 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used malicious shortcut files and legitimate cloud services for information theft and command execution.
Using malicious QR codes in spear-phishing campaigns for credential harvesting and mobile malware delivery, including trojanized Android APKs that provide remote access to victim devices.
Conducting phishing-based malware delivery using fake Webex meeting pages and security software spoofing pages to install an HttpSpy variant RAT.
More Articles 위협 인텔리전스Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.