Kimsuky
G00944 reportsAnalyst assessment — key judgments
- Signature techniques: T1588.006 (Vulnerabilities), T1589.001 (Credentials), T1588.007 (Artificial Intelligence).
- Primary targeting: KP, KR, PL, US.
- Steady activity: 1 report(s) in last 30d vs 2 prior (-50%).
- Recent movement: 33 new technique(s), 31 new infrastructure indicator(s) in the last 30 days.
- Hunt coverage 28% of 39 observed techniques (28 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
Movement — last 30 days
Vulnerabilities in this actor's reporting · 4
- CVE-2026-65400KEV1 rpt
- CVE-2026-68820KEV1 rpt
- CVE-2026-534131 rpt
- CVE-2026-713621 rpt
Overview
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.(Citation: EST Kimsuky April 2019)(Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: CISA AA20-301A Kimsuky)(Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024)
Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).(Citation: Netscout Stolen Pencil Dec 2018)(Citation: EST Kimsuky SmokeScreen April 2019)(Citation: AhnLab Kimsuky Kabar Cobra Feb 2019) In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.(Citation: MSFT-AI)
DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.
ATT&CK technique matrix
- T1588.006 · Vulnerabilitiesconf 652
- T1589.001 · Credentialsconf 652
- T1588.007 · Artificial Intelligenceconf 601
- T1213.002 · Sharepointconf 601evidence: 17th August – Threat Intelligence Report
- T1684 · Social Engineeringconf 601evidence: 17th August – Threat Intelligence Report
- AML.T0016.002 · Generative AIconf 601evidence: 17th August – Threat Intelligence Report
- T1132.001 · Standard Encodingconf 601
- T1556.003 · Pluggable Authentication Modulesconf 601
- T1059.007 · JavaScriptconf 601
- T1543 · Create or Modify System Processconf 601
- T1539 · Steal Web Session Cookieconf 601
- T1036.005 · Match Legitimate Resource Name or Locationconf 601
Threat catalogue · engineering roadmap
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
Relationships
Activity
| Title | Source | Severity | Collected |
|---|