Skip to content

APT group profile

Kimsuky

North Korean cyberespionage group active since at least 2012, focused on foreign policy, national security and nuclear issues on the Korean Peninsula, that targets governments, think tanks, academia and defense through spearphishing and social engineering.

MITRE G0094 Espionage LATAM Updated

Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.

MITRE ATT&CK techniques

Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.

Reconnaissance

  • T1598.003 Phishing for Information: Spearphishing Link

Resource Development

Initial Access

  • T1190 Exploit Public-Facing Application
  • T1566.001 Phishing: Spearphishing Attachment
  • T1566.002 Phishing: Spearphishing Link

Execution

  • T1053.005 Scheduled Task/Job: Scheduled Task
  • T1059.001 Command and Scripting Interpreter: PowerShell
  • T1059.005 Command and Scripting Interpreter: Visual Basic
  • T1204.002 User Execution: Malicious File
  • T1204.004 User Execution: Malicious Copy and Paste

Persistence

  • T1176.001 Software Extensions: Browser Extensions
  • T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Stealth

  • T1036.007 Masquerading: Double File Extension

Credential Access

  • T1003.001 OS Credential Dumping: LSASS Memory
  • T1056.001 Input Capture: Keylogging
  • T1539 Steal Web Session Cookie
  • T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Lateral Movement

  • T1021.001 Remote Services: Remote Desktop Protocol

Collection

  • T1114.003 Email Collection: Email Forwarding Rule

Command and Control

  • T1102.002 Web Service: Bidirectional Communication
  • T1219.002 Remote Access Tools: Remote Desktop Software

Exfiltration

  • T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage

Malware and tools

References

Public sources this profile is based on.

  1. [1] Kimsuky, Group G0094 · MITRE ATT&CK
  2. [2] North Korean Advanced Persistent Threat Focus: Kimsuky (AA20-301A) · CISA / FBI / USCYBERCOM CNMF, Oct 2020
  3. [3] APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations · Mandiant / Google Cloud, Mar 2023
  4. [4] Kimsuky targets organizations with PebbleDash-based tools · Kaspersky, May 2026

Profile last updated:

Concerned about this group?

The Ventura Systems MDR service monitors the techniques of this and other actors 24/7, with ATT&CK-based threat hunting.