- Home
- APT groups
- Kimsuky
APT group profile
Kimsuky
North Korean cyberespionage group active since at least 2012, focused on foreign policy, national security and nuclear issues on the Korean Peninsula, that targets governments, think tanks, academia and defense through spearphishing and social engineering.
Draft pending review. This profile was compiled from public sources and has not yet been validated by a Ventura Systems analyst. Check the references before using it for operational decisions.
Overview
Kimsuky is a North Korea-based cyberespionage group that MITRE ATT&CK considers active since at least 2012. Its priority is intelligence collection on foreign policy, national security, the nuclear program and sanctions related to the Korean Peninsula. It began by targeting South Korean government agencies, think tanks and subject-matter experts, and later expanded its scope to the United Nations and to government, education, business services and manufacturing organizations in the United States, Japan, Russia and Europe.
Mandiant/Google tracks an overlapping cluster, APT43, which it attributes to the Reconnaissance General Bureau (RGB). According to that report, the group funds part of its operations through cybercrime, particularly crypto-asset theft and laundering, to pay for its infrastructure. MITRE also documents the use of commercial language models since 2023 to research vulnerabilities, prepare scripts and draft lures.
Unlike Lazarus, Kimsuky rarely seeks destructive impact or financial theft as an end in itself. Its targets are people: the mailboxes, credentials and documents of analysts, diplomats and officials. For Latin America its relevance is limited but real: Kaspersky reported compromises of defense organizations in Brazil in 2026.
Notable campaigns
- 2014, Korea Hydro & Nuclear Power: MITRE includes this compromise among the operations attributed to the group (MITRE).
- 2018–2019, STOLEN PENCIL, Kabar Cobra and Smoke Screen: public operations against academia, think tanks and South Korean targets, listed in the MITRE entry.
- 2020, joint U.S. advisory: CISA, FBI and USCYBERCOM described the use of BabyShark, malicious browser extensions, a modified TeamViewer and the impersonation of journalists to contact Korea policy experts.
- 2023, APT43: Mandiant/Google documented fictitious personas impersonating diplomats and researchers, along with the use of stolen crypto assets to fund infrastructure.
- 2026, PebbleDash and AppleSeed: Kaspersky detailed HelloDoor, a Rust backdoor with traces of LLM-generated code, as well as abuse of VSCode tunnels, Cloudflare Quick Tunnels and DWAgent. It reported victims in South Korea and defense organizations in Brazil and Germany.
Key TTPs
Reconnaissance and resource development. It sends emails with links and web beacons to profile the victim (T1598.003), creates email accounts impersonating journalists, academics or officials (T1585.002) and registers domains that mimic organizations or search engines (T1583.001).
Initial access. It uses spearphishing with compressed Office, HWP, LNK or JSE attachments (T1566.001) or with links (T1566.002). Beforehand, it often maintains several “clean” exchanges to build trust. It has also exploited exposed servers, such as Exchange with CVE-2020-0688 (T1190).
Execution. It relies on the victim opening the file (T1204.002) and, more recently, on ClickFix-style lures that lead the victim to paste commands (T1204.004). It uses PowerShell and VBScript (T1059.001, T1059.005).
Persistence and evasion. It relies on Run keys (T1547.001), scheduled tasks (T1053.005), malicious Chrome extensions (T1176.001) and double-extension files, such as .pdf.lnk (T1036.007).
Credential access. It logs keystrokes (T1056.001), steals credentials and cookies from browsers (T1555.003, T1539) and dumps LSASS with Mimikatz or ProcDump (T1003.001).
Collection, C2 and exfiltration. It creates forwarding rules in compromised mailboxes (T1114.003), gains access via RDP (T1021.001) and uses legitimate remote desktop tools (T1219.002). For C2 it abuses Blogspot, GitHub or Dropbox (T1102.002), and it exfiltrates to cloud storage (T1567.002).
Detection and mitigation
- Email and impersonation: publish DMARC with a
p=quarantineorp=rejectpolicy on all owned domains. Flag as external any messages claiming to come from journalists, embassies or research centers, and verify requests through another channel (M1054, M1017). - High-risk attachments: block or sandbox LNK, JSE, HTA, PIF, SCR and CHM files inside archives. Block macros from the Internet (M1042, M1049) and alert when
wscript,mshtaorpowershellare launched from Outlook, File Explorer or%TEMP%. - ClickFix: restrict the Run dialog (Win+R) and PowerShell for users without an operational need. Search the RunMRU history for commands containing
powershell,mshtaorcurl. - Identity and cloud email: require phishing-resistant MFA (FIDO2) for diplomatic, defense, academic and international affairs staff (M1032). Audit forwarding rules and IMAP or legacy application access in Microsoft 365 and Google Workspace.
- Browsers: use policy-based extension allowlists (M1033) and monitor access to
Login Data,CookiesandLocal Stateby processes other than the browser. - Remote access and tunnels: alert on executions of
code.exe tunnel, DWAgent, Ngrok, Cloudflare Tunnel or TeamViewer on machines where they are not authorized, and on new local accounts added to the Remote Desktop Users group. - Telemetry: Sysmon (events 1, 3, 11 and 13), Windows events 4688, 4698 and 4720/4732, PowerShell 4104 logs and mailbox auditing (MailItemsAccessed, New-InboxRule).
- Regional priority: defense organizations, foreign ministries, universities and think tanks in LATAM that work on Asia-Pacific or nonproliferation issues should include this profile in their threat modeling.
MITRE ATT&CK techniques
Techniques attributed to the group in public sources, grouped by tactic. Each ID links to attack.mitre.org.
Reconnaissance
- T1598.003 Phishing for Information: Spearphishing Link
Resource Development
Initial Access
Execution
Persistence
Stealth
- T1036.007 Masquerading: Double File Extension
Credential Access
Lateral Movement
- T1021.001 Remote Services: Remote Desktop Protocol
Collection
- T1114.003 Email Collection: Email Forwarding Rule
Command and Control
Exfiltration
- T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Malware and tools
References
Public sources this profile is based on.
- [1] Kimsuky, Group G0094 · MITRE ATT&CK
- [2] North Korean Advanced Persistent Threat Focus: Kimsuky (AA20-301A) · CISA / FBI / USCYBERCOM CNMF, Oct 2020
- [3] APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations · Mandiant / Google Cloud, Mar 2023
- [4] Kimsuky targets organizations with PebbleDash-based tools · Kaspersky, May 2026
Profile last updated: