Kimsuky
This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
North Korean cyber espionage APT known for tailored spear-phishing and AppleSeed malware.
Kimsuky (also tracked as APT43, Emerald Sleet) is a North Korean nation-state threat actor conducting cyber espionage. It primarily targets South Korean government entities, defense, and energy sectors, along with diplomatic and academic targets in Germany. The group leverages personalized phishing for initial access, utilizing tools like Mimikatz for credential access and deploying customized malware such as AppleSeed and BabyShark. Defenders should focus on monitoring for tailored spear-phishing campaigns and suspicious browser extensions targeting Chromium-based browsers.
This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
Monitor email content and sender information to detect and prevent suspicious phishing activities.
Monitor network traffic and system changes related to malware development and distribution.
Use email security solutions and educate users to detect and prevent phishing attacks.
Use endpoint security solutions to detect and prevent execution of malicious files.
Monitor browser extension modifications and new extension installations.
Monitor system changes to detect and prevent file association modifications.
Monitor system and network activities to detect suspicious local account activities and execution delay tactics.
Monitor network traffic to detect unencrypted authentication data.
Monitor endpoint activities to detect suspicious activities related to browser information collection.
Monitor RDP connections to detect suspicious lateral movements.
Monitor endpoint activities to detect suspicious activities related to data collection from local system.
Monitor network traffic to detect suspicious ingress tool transfer activities.
Monitor network traffic and system activities to detect automated exfiltration activities.
Monitor system activities to detect suspicious activities related to disabling or modifying security tools.
Monitor system activities to detect suspicious activities related to service stop.
Kimsuky primarily targets South Korean government entities, defense, energy sectors, nuclear power operators, think tanks, industry, the Ministry of Unification, as well as diplomatic and academic targets in Germany.
The Kimsuky group uses the Mimikatz tool for credential access.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.