← All Threat Actors
Threat Actor Profile

Kimsuky

APT43 Black Banshee Earth Kumiho Emerald Sleet G0086 G0094 Operation Stolen Pencil PatheticSlug Sparkling Pisces Springtail TA427 Thallium Velvet Chollima
⚠ Critical Threat
Quishing Campaign, Software Vendor Supply Chain Attack, Operation GitPower
Origin North Korea
Sponsor Democratic People's Republic of Korea (DPRK) / Reconnaissance General Bureau (RGB)
Motivation Strategic espionage (nuclear policy, national security, sanctions) and cryptocurrency theft

Target Sectors

Think Tanks Academic Institutions Government Agencies Diplomatic Missions Collaborative Software Vendors (SaaS) Cryptocurrency Firms Defense and Military Researchers NGOs

Known TTPs

Quishing (QR Code Phishing) to bypass email security and MFA
Integration of local LLMs (Ollama, GPT4All, Msty) for malware development and data analysis
Supply chain attacks targeting software vendors to reach downstream customers
Abuse of Git-based repositories (GitHub/GitLab) for C2 infrastructure (Operation GitPower)
Spoofing of legitimate security software installation pages and Webex meetings
Session token theft and replay for cloud identity hijacking
DMARC spoofing to conceal spear-phishing origins
Deployment of custom malware including Gomir (Linux), Durian (Golang), and HTTPSpy
Use of .msc (MMC) files disguised as documents to execute shellcode

External Resources

CISA Advisories ↗

Related Intelligence


LINK COPIED TO CLIPBOARD