Kimsuky
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Kimsuky is a North Korean state‑sponsored advanced persistent threat group also tracked under the aliases Velvet Chollima, Thallium and Black Banshee. It is publicly linked to the Reconnaissance General Bureau intelligence agency and described by U.S. authorities as likely tasked by the North Korean regime with a global intelligence gathering mission. The group’s primary strategic objective is espionage, seeking to collect sensitive information from governmental, diplomatic and research targets.
Its activities focus on South Korean government entities such as the Ministry of Foreign Affairs, trade ministers and nuclear research institutes, while also extending to diplomatic missions, research organizations and universities that monitor North Korea’s nuclear program and sanctions. Financial institutions within South Korea, United Nations officials and similar bodies in Europe and North America have also been observed as victims. The group relies heavily on spear‑phishing emails that deliver malicious archive files containing JavaScript droppers, which use MSXML Base64 decoding and certutil.exe to retrieve an encoded DLL payload known as AppleSeed. AppleSeed is packed with UPX, employs custom encryption for API calls and strings, and collects keystrokes, screenshots, documents and removable device data before exfiltrating it via encrypted HTTP POST requests and then deleting the artifacts from the victim machine. In addition to the Windows variant, Kimsuky has deployed an Android version of AppleSeed that uses the same command‑and‑control infrastructure. The actors reuse phishing infrastructure for both credential harvesting and command‑and‑control communications, create fake login portals that mimic legitimate websites, and leverage Twitter and Gmail accounts for target reconnaissance, phishing lures and domain registration.
Representative operations include a 2021 campaign that used the AppleSeed backdoor to target South Korean government agencies through spear‑phishing emails with weaponized archive files, a 2021 intrusion of a South Korean nuclear research institute achieved by exploiting a VPN vulnerability that allowed thirteen unauthorized IP addresses—one linked to Kimsuky—to access the internal network, a 2020 spear‑phishing effort directed at United Nations officials that employed emails masquerading as security alerts or interview requests and leveraged both email and WhatsApp channels, and a 2019 phishing operation that deployed fraudulent login pages mimicking the diplomatic portals of France, Slovakia, the United Kingdom and the United States, as well as university and think‑tony sites, to harvest credentials for espionage purposes. These examples illustrate the group’s consistent focus on intelligence collection through credential theft, custom malware and socially engineered access vectors.
Incidents
Attributed incidents are available to members.
12 incidents