Kimsuky is a North Korea-linked espionage threat actor focused primarily on intelligence collection in support of Pyongyang’s strategic interests. The group is widely tracked under multiple aliases including APT43, Thallium, Emerald Sleet, Velvet Chollima, TA406, Springtail, Black Banshee, Cerium, Opal Sleet, Ruby Sleet, Osmium, SharpTongue, Sparkling Pisces, and Earth Imp. Reporting has also associated Kimsuky with names such as APT-C-55, Planedown, GreenDinosa, and TA427. Some alias overlap in public reporting can be inconsistent, but Kimsuky and APT43 are among the most commonly used identifiers. Kimsuky has repeatedly targeted South Korean government-adjacent entities, diplomatic personnel, academia, research organizations, software and groupware vendors, and other organizations of intelligence value. The group is also known to target think tanks, media, education-sector personnel, and individuals connected to foreign affairs and policy. Recent activity shows continued emphasis on South Korean victims, including diplomacy-related targets and collaborative software supply chains, with downstream compromise of customer environments after vendor intrusion. The actor relies heavily on spear-phishing and social engineering for initial access. Common delivery methods include malicious shortcut files, decoy documents, embedded script content, and lures themed around work, diplomacy, resumes, surveys, or policy matters. Kimsuky has also been observed using cloud and developer platforms such as Dropbox, GitHub, Google Drive, and similar legitimate services for payload delivery, command execution, staging, and information theft. In some campaigns the group has incorporated newer social-engineering delivery patterns such as ClickFix-style user-assisted execution. Observed tradecraft includes extensive use of PowerShell, HTA, JavaScript, batch scripts, Python, scheduled-task persistence, DLL side-loading, process injection, and abuse of legitimate administration or remote-access tooling. Kimsuky has deployed backdoors, infostealers, keyloggers, proxy tools, downloaders, and remote administration components, and has used UAC bypass techniques, RDP enablement, account manipulation, and multi-session remote desktop modification to maintain access and facilitate hands-on operations. The group has also used fake login pages to harvest credentials and has leveraged stolen configuration data or authentication material to pivot from compromised vendors into customer networks. Malware and tooling associated with Kimsuky include PebbleDash, PrxClient, Gomir, BirdTroy, DriveTroy, HttpTroy, BirdTroy, DriveTroy, and related Go-based Linux backdoors, as well as earlier families and variants linked through code, infrastructure, and operational overlap. Recent reporting highlights Kimsuky’s use of Linux malware in addition to Windows implants, including Go-based backdoors that support persistence through system services or cron, shell execution, file transfer, proxying, and cloud-backed command-and-control. BirdTroy introduced HTTP/3-capable communications, while DriveTroy abused Google Drive as a command channel. Campaigns against South Korean groupware vendors also involved lateral movement, credential theft, remote access tooling, and supply-chain-style follow-on targeting of customers. Kimsuky’s operational pattern is consistent with long-term espionage rather than disruptive or destructive activity. The group prioritizes credential theft, document collection, host reconnaissance, remote control, and covert persistence. Its targeting of diplomats, foreign-policy personnel, software vendors, and downstream enterprise environments reflects a sustained intelligence requirement and an ability to adapt delivery mechanisms, malware families, and infrastructure while continuing to exploit trusted services and socially engineered execution paths.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
51 malware families attributed to this actor across reporting.
46 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
APT28 has used a variety of public exploits, including CVE 2020-0688 ... to gain execution on vulnerable Microsoft Exchange... Dragonfly ... exploited ... CVE-2020-0688 for ... MS Exchange... Kimsuky ... including Microsoft Exchange vulnerability CVE-2020-0688. MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
DPRK aligned TA406 (Opal Sleet) chained CVE-2026-21510 with CVE-2026-21509 in active campaigns.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
10 more CVEs tied to this actor tracked in Mallory.
1,673 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the threat actor behind a malware sample delivered via a malicious .lnk file themed as a survey form related to agricultural/food-sector AX implementation status.
Mentioned only as a tag in an AhnLab June 2026 South Korea APT trend report; the body does not explicitly attribute any described activity cluster or attack type to Kimsuky.
Kimsuky is only mentioned as a tag in this monthly domestic APT trend report; the report does not attribute the described activity types to Kimsuky.
Mentioned only as broader threat-landscape context related to North Korean activity against diplomatic entities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.