Kimsuky is a long-running North Korea-linked cyber-espionage malware cluster and associated toolset used primarily against South Korean government entities, think tanks, political organizations, and other strategically relevant targets. Activity associated with this name has included weaponized Hangul Word Processor and Microsoft Office documents, malicious shortcut files, script-based loaders, and modular backdoors designed for intelligence collection and remote access on Windows systems.
Observed Kimsuky malware has delivered and installed backdoors through document exploits, externally linked Office templates, and socially engineered lure files masquerading as business or policy documents. Document-based infection chains have used malicious HWP files exploiting Hangul vulnerabilities, as well as Word documents that retrieve remote content and execute obfuscated VBA or script stages. Other campaigns have used disguised Windows shortcut files that launch PowerShell or JavaScript, extract decoy documents, and establish persistence through scheduled tasks.
The malware ecosystem associated with Kimsuky supports host reconnaissance, credential and information theft, keylogging, exfiltration, persistence, and defense evasion. Reported functions include collecting system and user information, process listings, network details, recently modified files, and other host telemetry; stealing emails and passwords from web forms; logging keystrokes; and uploading stolen data to attacker-controlled infrastructure or external services. Some variants have used webmail accounts as a command-and-control and exfiltration channel, while others have used cloud services such as Dropbox or abused legitimate web services to stage payloads and retrieve commands. Modular components and loaders have also supported in-memory execution of follow-on payloads and remote-control functionality, including use of modified TeamViewer components in some campaigns.
Persistence mechanisms have included Windows services and scheduled tasks. Defense-evasion behavior has included obfuscation, fileless PowerShell execution, self-deletion of initial lures, timestomping, use of decoy documents, and attempts to weaken host protections by disabling or modifying firewall and security-center settings. Some samples have also included privilege-escalation or UAC-bypass techniques.
Kimsuky is best understood not as a single binary family but as an evolving espionage malware set and operational framework tied to a North Korean threat actor. Across campaigns, the tooling has been consistently aligned with targeted collection operations rather than disruptive or destructive objectives, with a strong emphasis on stealthy access, victim profiling, and theft of sensitive information from Windows endpoints.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kimsuky 조직 악성 HWP 한글 문서 유포 – ASEC BLOG 10월 16일 어제 안랩 ASEC 분석팀에 새로운 악성 HWP 한글 문서가 접수되었다. 확인 결과 Kimsuky 조직 유형으로 판단된다.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content compares the information-stealing PowerShell script’s behavior to past Kimsuky-linked activity, but does not identify a specific malware family name beyond that reference.
A malicious LNK-based infection chain attributed in the content to Kimsuky. It disguises itself as an Excel document, extracts decoy and payload files from the LNK, establishes persistence via a scheduled task, runs a JavaScript launcher and PowerShell payload, and uses Dropbox API as C2 to upload victim information and download BAT commands for execution.
Mentioned in related/background content as an actor associated with malicious HWP document distribution, not as the primary malware family in this article.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.