130
Techniques
19
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

View MITRE record ↗

Techniques by Tactic (130)
Toolsets (19)
🐛
Amadey S1025
Malware · Windows
🐛
AppleSeed S0622
Malware · Windows, Android
🐛
BabyShark S0414
Malware · Windows
🐛
Malware · Windows
🐛
GoBear S1197
Malware · Windows
🐛
Malware · Windows
🐛
Gomir S1198
Malware · Linux
🐛
HTTPTroy S9007
Malware · Windows
🐛
KGH_SPY S0526
Malware · Windows
🐛
NOKKI S0353
Malware · Windows
🐛
Malware · Windows
🐛
Malware · Windows
🐛
gh0st RAT S0032
Malware · Windows, macOS
🔧
Tool · Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
PsExec S0029
Tool · Windows
🔧
QuasarRAT S0262
Tool · Windows
🔧
certutil S0160
Tool · Windows
🔧
schtasks S0111
Tool · Windows
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
References & Reports (17)
↑