THREATOPS Actor Dossier
LIVE ← Dashboard

Kimsuky

G00944 reports
aliases · Kimsuky · Black Banshee · Velvet Chollima · Emerald Sleet · THALLIUM · APT43 · TA427 · Springtail · Earth Kumiho · PatheticSlug
Export dossier:
4
Reports
12
Techniques
9
Tactics
7
Countries
28%
Hunt coverage
10
Aliases

Analyst assessment — key judgments

  • Signature techniques: T1588.006 (Vulnerabilities), T1589.001 (Credentials), T1588.007 (Artificial Intelligence).
  • Primary targeting: KP, KR, PL, US.
  • Steady activity: 1 report(s) in last 30d vs 2 prior (-50%).
  • Recent movement: 33 new technique(s), 31 new infrastructure indicator(s) in the last 30 days.
  • Hunt coverage 28% of 39 observed techniques (28 gap(s)).
  • Assessment confidence: medium (60).

Activity & trend

SteadyLast 30d: 1 vs 2 prior (-50%)· first reported 2026-07-16 · last 2026-09-04
0
7d
1
30d
4
90d
4
All
0.3
Rpts/wk
Reporting timeline · 12 months

Movement — last 30 days

New techniques
T1132.001T1556.003T1059.007T1543T1539T1036.005T1497.001T1119T1082T1071T1106T1190
Targeting lost
BRINPLTWUS
New infrastructure
4bb923eb040aa13ca8fd409c31ee4729c60ddff35db1b6d52faf60b4f32d6fd0c7c938e4d05d29a109739441ed4599bac2f8159028f772f71e4b25c8fea1bc36632c71e5a839803469ef60ac47595d36feeea9d0bf6ae7396d28271baa51ae50df5169ce8f30b57928934ae67478d0e690c91d046e35a63872e70936f0dbe459142a1d867617c35f8d0cce5da8bfab4de81a1acb04aacdf757346946b0f5e30f83f7d565b0465546027052b597af46eae3a199e77007a78d50a993cb174c685eba96eb442c9507e36cf1b5e92a9c0756f597a5ddefb38eba32961c52ed72f4cd8d467b5c5d95ae6aeca4aaeea14d7956

Vulnerabilities in this actor's reporting · 4

Overview

Analyst triage
Intelligence summary

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.(Citation: EST Kimsuky April 2019)(Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: CISA AA20-301A Kimsuky)(Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024)

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).(Citation: Netscout Stolen Pencil Dec 2018)(Citation: EST Kimsuky SmokeScreen April 2019)(Citation: AhnLab Kimsuky Kabar Cobra Feb 2019) In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.(Citation: MSFT-AI)

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

Top co-occurring indicators
    Aliases & naming
      Targeting · countries
        Targeting · named victims

          ATT&CK technique matrix

          Coverage vs hunt library:
          Hunt-coverage gaps — prioritized

            Top techniques by observation

            Threat catalogue · engineering roadmap0

            Flagged detection-engineering queue

            Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.

              No techniques queued yet — flag a gap above to add it here.

              Infrastructure

              IOC type mix
              Tooling / malware families
                Tracked infrastructure

                Relationships

                Related actors (behavioral cluster)
                  Attributed malware
                  Campaigns
                  No behavioral cluster, attributed malware, or campaigns recorded for this actor yet.

                  Activity

                  30-day mention timeline
                  Recent reporting
                  TitleSourceSeverityCollected