Kimsuky is a North Korea-linked cyber espionage threat actor active since at least 2013 and widely tracked under aliases including APT43, Thallium, Velvet Chollima, Emerald Sleet, TA406, TA408, TA427, Springtail, Black Banshee, Cerium, Opal Sleet, Ruby Sleet, Osmium, and SharpTongue. The group is associated with intelligence collection in support of DPRK strategic interests and has repeatedly targeted individuals and organizations connected to South Korea, North Korean affairs, unification policy, scientific and engineering research, diplomacy, and human rights work focused on North Korea. Kimsuky is known for sustained spearphishing and credential-harvesting operations, often using socially engineered emails, fake login pages, and malicious document attachments in Word, Excel, and Hangul Word Processor formats. Reported tradecraft includes theft of browser-stored passwords and cookies, use of browser extensions and credential-dumping utilities, PowerShell-based keylogging, and collection of session data from webmail and browser activity. The actor has also used scripts and downloaders to retrieve additional payloads, abused native Windows utilities such as regsvr32 and mshta for execution, and employed hidden PowerShell execution for defense evasion. The group operates custom malware families and implants, including AppleSeed and AutoIT-based tooling. In Operation Newton, Kimsuky used phishing to steal webmail credentials from scientific and engineering researchers, then leveraged stolen email, VPN, and server credentials to access internal environments, move laterally across Windows and Linux systems, deploy web shells and reverse shells, and exfiltrate research data. AppleSeed variants have supported persistence, command execution, monitoring, upload and download of files, and collection of host information; related reporting also identified Android malware variants tied to the same malware lineage. Separate reporting has linked Kimsuky tradecraft to Android-focused operations using Firebase Cloud Messaging for command and control, although some individual mobile campaigns remain only overlap-based rather than conclusively attributed. Kimsuky has shown particular interest in South Korean civil society and North Korea-focused communities, including activists, journalists, professors, NGOs, and human rights defenders. The actor has also been associated with compromise of accounts and follow-on social engineering through trusted messaging relationships. Its operations emphasize practical credential theft, persistence, and post-compromise exploitation over technically novel intrusion methods, while maintaining enough operational flexibility to use custom malware, staged payload delivery, and cross-platform tooling when needed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
55 malware families attributed to this actor across reporting.
50 additional families tracked in Mallory.
17 CVEs this actor has used in observed campaigns. 17 of them exploited in the wild.
APT28 has used a variety of public exploits, including CVE 2020-0688 ... to gain execution on vulnerable Microsoft Exchange... Dragonfly ... exploited ... CVE-2020-0688 for ... MS Exchange... Kimsuky ... including Microsoft Exchange vulnerability CVE-2020-0688. MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
DPRK aligned TA406 (Opal Sleet) chained CVE-2026-21510 with CVE-2026-21509 in active campaigns.
CVE-2024-1708 (CVSS:8.4) is a path traversal vulnerability that can allow an attacker to execute code remotely on the ScreenConnect server. Together, CVE-2024-1709 and CVE-2024-1708 can allow a threat actor to perform remote code execution post authentication.
Two critical vulnerabilities, tracked as CVE-2024-1708 and CVE-2024-1709, were recently addressed in ConnectWise ScreenConnect and have been exploited by many threat actors due to its ease of exploitability. CVE-2024-1709 (CVSS:10) can allow for authentication bypass due to insufficient path filtering.
12 more CVEs tied to this actor tracked in Mallory.
2,676 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of the most active APT groups in April 2026, operating out of East Asia and associated with attacks largely using spear-phishing against South Korean entities including organizations, individuals, financial institutions, and research institutions.
Conducting spear-phishing-led espionage operations against Korea-related political, diplomatic, media, think-tank, academic, and government-linked targets using a multi-stage infection chain and carefully gated C2 infrastructure.
Described as creating malware named Review.chm and targeting a defector identified as Dr. Jo in the livestock/veterinary field.
Likely linked to hosting or administering infrastructure containing a copy of XenoRAT; the article also references a likely North Korea-linked group using XenoRAT.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.