TLP:CLEAR
⚠ NATION-STATE · RECONNAISSANCE GENERAL BUREAU (RGB) · NORTH KOREA (DPRK)
// Threat Actor Profile — DPRK State-Directed Cyber Espionage & Self-Funding Financial Cybercrime Collective

KIMSUKY

PROFILE COMPILED: 2026-09-02  |  SOURCES: MITRE ATT&CK (G0094), CISA/FBI Joint Advisory AA20-301A, FBI IC3 FLASH AC-000001-MW (Jan 2026), U.S. Treasury/OFAC, Mandiant/Google GTIG (APT43), Microsoft Threat Intelligence (Emerald Sleet), Kaspersky/Securelist, Trellix, Enki WhiteHat, The Hacker News, DomainTools, 16+ additional vendor/press sources
Status: ACTIVE — ESCALATING, AI-AUGMENTED TRADECRAFT
Threat Level: HIGH
Primary Motive: State-Directed Foreign Policy/Nuclear Intelligence Collection + Self-Funding Cybercrime
Active Since: 2012 (assessed)
MITRE ATT&CK: G0094
⚡ THREAT UPDATE — AUG 2026
Operation GitPower: Kimsuky builds an offline AI stack to accelerate phishing lures and malware development
Reporting published in August 2026 documents Kimsuky assembling a self-hosted, offline large-language-model stack — including Ollama, GPT4All, and Msty — deliberately kept off external cloud AI platforms to avoid the abuse-detection telemetry those vendors maintain, while extending an active campaign ("Operation GitPower") that abuses GitHub repositories as a covert C2 channel within an LNK-to-PowerShell infection chain distributing AsyncRAT payloads disguised as image files (The Hacker News, 2026-08). This follows a 2025 Genians finding that a Kimsuky spear-phishing operation used ChatGPT-generated images of South Korean military employee ID cards as lure content, and sits alongside a parallel FBI FLASH advisory (AC-000001-MW, 2026-01-08) documenting Kimsuky's use of malicious QR codes ("quishing") against foreign-policy think tanks, embassies, and NGOs since May 2025. No formal follow-on CISA/FBI advisory specific to the offline-AI-stack finding had been published as of this compile; treat the underlying campaign infrastructure as active and evolving.
14+
Years of Continuous Espionage Operations (Active Since 2012)
8
DPRK Agents + Group Sanctioned by US Treasury OFAC, Nov 30 2023 (with AU/JP/ROK)
19+
Embassy Spear-Phishing Emails in One Coordinated Campaign, Mar–Jul 2025 (Trellix)
20+
Distinct Malware Families & Tool Variants Tracked (MITRE G0094 + 2025-26 Reporting)
00
Overview

Kimsuky is a North Korea-based cyber espionage collective active since at least 2012, tracked by MITRE ATT&CK as G0094 and known across the vendor community under a wide range of names — Black Banshee, Velvet Chollima, THALLIUM, Emerald Sleet, APT43, TA427, Springtail, Earth Kumiho, and PatheticSlug among them (MITRE ATT&CK, accessed 2026-09-02). The group is assessed to operate under or in close coordination with North Korea's Reconnaissance General Bureau (RGB), the regime's primary foreign intelligence service, and its core tasking has remained consistent for over a decade: collect intelligence on foreign policy, nuclear negotiations, sanctions posture, and national-security decision-making tied to the Korean Peninsula (CISA AA20-301A, 2020).

Kimsuky matters now because it has not stood still. Where the group's earliest reporting centered on South Korean government, think-tank, and nuclear-industry targets — including a 2014 compromise of Korea Hydro & Nuclear Power Co. — its operations have expanded to embassies, foreign-policy institutions, and individual subject-matter experts across the United States, Japan, and Europe (MITRE ATT&CK; Trellix, 2025). Through 2025 and into 2026 the group has layered in QR-code "quishing" specifically engineered to move a victim's malicious click off a monitored corporate endpoint and onto a personal mobile device (FBI IC3 FLASH AC-000001-MW, 2026-01-08); pivoted into supply-chain intrusions against South Korean groupware vendors to reach their downstream customers (Enki WhiteHat, 2026); and, as of August 2026, begun operationalizing offline large-language-model tooling to accelerate lure generation and malware development while deliberately avoiding the abuse-detection telemetry maintained by cloud AI vendors (The Hacker News, 2026-08).

Kimsuky sits within a broader North Korean state cyber ecosystem alongside Lazarus Group and Andariel — sibling RGB-linked clusters with overlapping but distinct mission sets (Anthropic Threat Intelligence Report, Aug 2025). Unlike those more destructively- or financially-focused units, Kimsuky's defining characteristic is that it targets people as much as networks: named foreign-policy analysts, retired and active diplomats, and journalists covering the Korean Peninsula are recurring, individually-selected victims, not incidental catches of an enterprise-wide intrusion. Mandiant's 2023 APT43 reporting also documented the group engaging in financially-motivated cryptocurrency theft and laundering — via stolen wallets and cloud-mining/hash-rental services — explicitly to self-fund its own operational needs rather than draw on state budget, a pattern consistent with the sanctions-pressured regime's broader push toward cyber-enabled hard-currency generation (Mandiant, 2023).

The critical operational context for 2026 is twofold: first, Kimsuky remains squarely within the U.S. government's active exploited-vulnerability picture — CVE-2024-1708 in ConnectWise ScreenConnect, which Kimsuky weaponized to deploy the ToddlerShark malware variant, sits on CISA's Known Exploited Vulnerabilities catalog. Second, the group's growing reliance on legitimate, trusted platforms — GitHub, Google Drive, Dropbox, VS Code remote tunnels — as command-and-control infrastructure means conventional domain- and IP-reputation-based network defenses are increasingly poor tools against it, raising the operational burden on user-level and behavioral detection instead.

01
Identity & Attribution
Primary NameKimsuky
Sponsor / ParentReconnaissance General Bureau (RGB), DPRK
Actor TypeNation-State APT — Espionage + Self-Funding Cybercrime
Primary MotivationForeign policy / nuclear-policy intelligence collection; secondary financial self-funding via cryptocurrency theft
Active Since2012 (assessed; earliest widely-reported operations 2013-2014)
Last ObservedAug 2026 (Operation GitPower, offline-AI-stack tradecraft)
MITRE G-IDG0094
Legal StatusOFAC-sanctioned (US Treasury, 30 Nov 2023, coordinated w/ AU/JP/ROK); no public indictment identified as of this compile
Tracking Aliases
Kimsuky (MITRE G0094) Black Banshee Velvet Chollima (CrowdStrike) THALLIUM (Microsoft, legacy) Emerald Sleet (Microsoft, current) APT43 (Mandiant/Google GTIG) TA427 (Proofpoint) Springtail (Symantec/Broadcom) Earth Kumiho (Trend Micro) PatheticSlug STOLEN PENCIL (2018 campaign name)
Attribution Confidence

[HIGH] confidence Kimsuky is a North Korea-directed cyber espionage collective operating under or in close coordination with the RGB. This rests on convergent, independently-derived attribution: a formal U.S. Treasury/OFAC sanctions action (30 Nov 2023, coordinated with Australia, Japan, and South Korea) explicitly naming Kimsuky as RGB-controlled; a joint CISA/FBI advisory (AA20-301A, 2020); and consistent technical and infrastructure tradecraft independently tracked since at least 2018 by Mandiant/Google GTIG (as APT43), Microsoft (as Emerald Sleet, formerly THALLIUM), CrowdStrike (as Velvet Chollima), and Kaspersky. A residual [MEDIUM] gap exists at the organizational-boundary level: Mandiant's original APT43 designation explicitly folded prior "Kimsuky"/"Thallium" reporting into one cluster distinguished partly by self-funding cryptocurrency operations, while MITRE ATT&CK (G0094) and most other public reporting treat all of the above names as one continuously-tracked entity. Whether this reflects a single team with an evolving mission set, or multiple RGB-directed sub-units sharing tooling and infrastructure, is not resolved in the open-source reporting reviewed for this compile.

02
Campaign & Operational Timeline
2012–2018
Origins & South Korea-Focused Espionage
Earliest tracked activity targets South Korean government agencies, think tanks, and subject-matter experts, using BabyShark-style PowerShell tooling for initial reconnaissance. A 2014 intrusion into Korea Hydro & Nuclear Power Co. is among the group's earliest widely-reported operations against critical national infrastructure adjacent targets (CISA AA20-301A, 2020).
SEP 2018
Operation STOLEN PENCIL
Campaign targeting academic institutions, primarily in South Korea, using browser-extension malware and credential-harvesting techniques to compromise researchers and students working on Korea-related subject matter — an early example of the group's individual-level, expert-targeted collection doctrine (MITRE ATT&CK G0094).
2019
Operation Kabar Cobra & Operation Smoke Screen — International Expansion
Kimsuky's targeting footprint expands beyond South Korea to include UN offices and organizations across government, education, and business sectors in the United States, Japan, Russia, and Europe, alongside continued targeting of retired South Korean diplomats and military officials (MITRE ATT&CK G0094; reporting, Aug 2019).
OCT 2020
CISA/FBI Joint Advisory AA20-301A
CISA and the FBI publish "North Korean Advanced Persistent Threat Focus: Kimsuky," the first major U.S. government-formalized public profile of the group, consolidating years of tradecraft observation — tailored spear-phishing, exploitation of known software vulnerabilities post-access, and persistence techniques — into a single reference advisory still cited in current reporting.
MAR–NOV 2023
Mandiant APT43 Report & U.S./Allied OFAC Sanctions
Mandiant publishes its APT43 profile (Mar 2023), documenting the group's self-funding cryptocurrency theft and laundering operations via cloud-mining and hash-rental services, and noting early adoption of large language models for reconnaissance and social-engineering content generation. On 30 Nov 2023, the U.S. Treasury, coordinated with Australia, Japan, and South Korea, sanctions Kimsuky and eight foreign-based agents in direct response to North Korea's Nov 1, 2023 military-reconnaissance satellite launch.
2024
CVE-2024-1708 Exploitation — ToddlerShark
Kimsuky actively exploits CVE-2024-1708, a path-traversal vulnerability in ConnectWise ScreenConnect (CVSS 8.4), to deploy a polymorphic malware variant tracked as ToddlerShark — marking a shift toward technical exploitation of internet-facing remote-management software as a complement to social engineering.
MAR 2025–JAN 2026
Embassy GitHub-C2 Campaign & FBI Quishing FLASH Advisory
Between March and July 2025, Trellix identifies at least 19 spear-phishing emails against diplomatic missions worldwide, impersonating trusted contacts and timing lures to real diplomatic events, delivering a XenoRAT variant via GitHub-hosted C2 and Dropbox/Daum-staged password-protected archives. In parallel, May–June 2025 campaigns embed malicious QR codes in emails to think tanks and foreign-policy advisory firms, culminating in the FBI's IC3 FLASH AC-000001-MW (8 Jan 2026), which formally warns NGOs, academia, and foreign-policy experts of the quishing technique.
2025–AUG 2026
Groupware Supply-Chain Intrusions & AI-Augmented Tradecraft
Enki WhiteHat tracks Kimsuky infiltrating South Korean groupware vendors' internal networks via mail-server RCE and spear-phishing, deploying Gomir/HttpTroy-derived BirdTroy and DriveTroy backdoors (the latter using Google Drive as its C2 channel), then pivoting laterally into customer-facing servers and tampering with vendor login pages to harvest downstream customer credentials. By August 2026, reporting documents "Operation GitPower" — GitHub-repository C2 for LNK-to-PowerShell AsyncRAT delivery — alongside an offline LLM stack (Ollama, GPT4All, Msty) assembled to accelerate phishing-lure and malware development while avoiding cloud-AI-vendor abuse telemetry.
03
Attack Lifecycle Social-Engineering-Led Espionage Chain with Legitimate-Service C2

Entry begins almost always with meticulously tailored spear-phishing that impersonates a known professional contact — a foreign policy advisor, embassy staff member, journalist, or think-tank peer — frequently timed to coincide with real, contemporaneous events (an EU meeting, a diplomatic luncheon, a conference) to lend the pretext credibility (Trellix, 2025). Since 2025 the group has layered in QR-code "quishing": embedding a malicious URL inside a QR code so the victim scans it with a personal mobile device, deliberately moving the malicious click off the monitored corporate endpoint and its email-security controls entirely, landing on fake conference-registration pages or spoofed Google account login pages built for credential harvesting (FBI IC3 FLASH AC-000001-MW, 2026). Where social engineering alone is insufficient, Kimsuky exploits internet-facing infrastructure directly — most notably CVE-2024-1708 in ConnectWise ScreenConnect, and, against South Korean groupware vendors, direct remote-code-execution against externally exposed mail servers.

Core initial-stage tooling has remained BabyShark (a PowerShell/VBS implant used for reconnaissance and lightweight C2 relay since 2018) and AppleSeed (a backdoor providing keylogging, screenshot capture, file exfiltration, and C2 communication). Mid-stage access increasingly relies on the PebbleDash malware cluster — HelloDoor, httpMalice, MemLoad, and httpTroy — and the newer Gomir/HttpTroy-derived family, whose 2025-2026 variants BirdTroy and DriveTroy extend targeting specifically to Linux server infrastructure at compromised software vendors. Credential and browser-data theft is handled by GoBear and Troll Stealer, alongside the older KGH_SPY spyware suite; dual-use tools including Mimikatz and PsExec support internal reconnaissance and lateral movement once inside a network.

A defining and increasingly consistent trait is Kimsuky's abuse of legitimate, trusted cloud and developer platforms as the command-and-control channel itself, rather than maintaining bespoke C2 infrastructure that carries its own reputation signal: GitHub repositories (Operation GitPower's LNK→PowerShell→AsyncRAT chain), Google Drive (DriveTroy), and Dropbox/Daum/Blogspot for payload staging and beaconing. This blends malicious network traffic into ordinary SaaS usage patterns and defeats domain-reputation- and IP-allowlist-based network detection that would flag traffic to unfamiliar infrastructure.

Once inside groupware-vendor environments, the group aggressively pursues lateral movement into customer-facing servers, harvests vendor infrastructure credentials, and tampers with compromised vendors' login pages to capture downstream customer credentials — a supply-chain amplification pattern distinct from Kimsuky's earlier, more purely espionage-driven operations. Persistence relies on scheduled tasks and autostart mechanisms, alongside abuse of Visual Studio Code's built-in remote-tunnel feature for durable, legitimately-signed remote access unlikely to trip EDR application-control policies tuned to traditional remote-access tools. Collected material — documents, credentials, screenshots, and cryptocurrency wallet contents — is archived and exfiltrated over the same abused C2 channel or via web-service upload.

04
TTPs — MITRE ATT&CK Mapping Enterprise framework; 13 techniques mapped
Reconnaissance
T1589
Gather Victim Identity Information
[HIGH] Extensive pre-attack profiling of named individuals (think-tank scholars, diplomats, journalists) to build credible impersonation pretexts before first contact (Trellix, 2025).
Resource Development
T1588.007
Obtain Capabilities: Artificial Intelligence
[HIGH] Offline LLM stack (Ollama, GPT4All, Msty) for phishing-lure and malware-development assistance kept off external cloud AI platforms to evade vendor abuse telemetry (The Hacker News, Aug 2026); ChatGPT-generated fake military ID imagery used as lure content (Genians, 2025).
Initial Access
T1566.001 / .002
Phishing: Spearphishing Attachment / Link
[HIGH] Tailored spear-phishing impersonating known professional contacts, timed to real diplomatic/policy events; primary and most consistent initial-access vector since 2012 (CISA AA20-301A).
Initial Access
T1190
Exploit Public-Facing Application
[HIGH] CVE-2024-1708 (ConnectWise ScreenConnect, CVSS 8.4) exploited to deploy ToddlerShark; separately, direct RCE against internet-facing mail servers at South Korean groupware vendors (Enki WhiteHat, 2026).
Execution
T1059.001
Command and Scripting Interpreter: PowerShell
[HIGH] BabyShark's core implant logic is PowerShell/VBS-based, in continuous use as an initial-stage tool since 2018 (MITRE ATT&CK G0094).
Execution
T1204.001
User Execution: Malicious Link
[HIGH] QR-code "quishing" specifically engineered to induce a personal-device scan-and-click outside corporate email-security controls (FBI FLASH AC-000001-MW, 2026).
Persistence
T1053.005
Scheduled Task/Job
[MEDIUM] Scheduled tasks used for backdoor persistence across the AppleSeed/PebbleDash tool clusters (MITRE ATT&CK G0094; CISA AA20-301A).
Defense Evasion
T1036
Masquerading
[HIGH] Spoofed subdomains mimicking legitimate Google/Yahoo mail login pages; AsyncRAT payloads disguised as image files in Operation GitPower (DomainTools; The Hacker News, 2026).
Defense Evasion
T1027
Obfuscated Files or Information
[MEDIUM] Consistent recompilation/rebranding of malware families (PebbleDash→HelloDoor/httpTroy; Gomir→BirdTroy/DriveTroy) to evade signature-based detection of prior variants (Securelist; Enki WhiteHat).
Credential Access
T1003
OS Credential Dumping
[HIGH] Mimikatz deployed post-access for credential harvesting; DomainTools' "Kim leak" analysis documented PAM password-change log artifacts consistent with systematic credential-theft workflow.
Credential Access
T1056.002
Input Capture: GUI Input Capture
[HIGH] Fake Google-account login pages served via QR-code landing flows to directly harvest entered credentials (FBI FLASH AC-000001-MW, 2026).
Collection
T1114
Email Collection
[MEDIUM] Sustained email-account access/collection consistent with the group's foreign-policy-intelligence collection doctrine (CISA AA20-301A).
Command & Control
T1102.002
Web Service: Bidirectional Communication
[HIGH] GitHub repositories (Operation GitPower) and Google Drive (DriveTroy) used directly as C2 channels, blending traffic into legitimate SaaS/developer platform usage (The Hacker News; Enki WhiteHat, 2026).
Exfiltration
T1567.002
Exfiltration to Cloud Storage
[MEDIUM] Dropbox and Daum used for password-protected archive staging and payload/data movement in the 2025 embassy campaign (Trellix, 2025).
05
Targeting Profile
Sector Targeting
Government & Diplomatic
PRIMARY
Think Tanks, NGOs & Academia
HIGH
Defense & National Security Policy
HIGH
Software / Groupware & IT Vendors
MED
Cryptocurrency & Financial Services
MED
GeographiesSouth Korea (primary, sustained); United States, Japan, and EU member states via diplomatic missions; global embassy targeting expansion observed 2025 (Trellix)
Victim ProfileNamed individuals more often than infrastructure alone — foreign policy analysts, retired/active diplomats, embassy staff, journalists covering the Korean Peninsula, nuclear-policy SMEs, plus enterprise targets at South Korean groupware/software vendors
Preferred EntryHuman-centric social engineering (impersonation spear-phishing, QR-code quishing) as primary vector; internet-facing RMM/mail-server exploitation as secondary vector where a technical foothold is required without a willing human step
Target DoctrineSelective, individual-level targeting aligned to DPRK foreign-policy intelligence requirements, supplemented by opportunistic financially-motivated cryptocurrency operations to self-fund continued espionage activity
06
Tools, Malware & Infrastructure
BABYSHARK LOADER/RECON · CUSTOM · T1059.001
PowerShell/VBS-based implant, in use since 2018, providing initial system profiling, lightweight C2 relay, and staging for follow-on backdoors. Remains a core first-stage tool despite its age, indicating continued operational reliance rather than replacement.
APPLESEED BACKDOOR · CUSTOM · T1114 / T1113
Backdoor with keylogging, screenshot capture, file exfiltration, and C2 communication capability; deployed after initial access as a mid-stage persistent implant. One of the two malware clusters (alongside PebbleDash) Kaspersky assesses as the group's most technically advanced tooling.
PEBBLEDASH CLUSTER (HelloDoor / httpMalice / MemLoad / httpTroy) BACKDOOR · CUSTOM · T1027
Family of related backdoors used for durable access and C2, with new tool naming (HelloDoor, httpMalice, MemLoad, httpTroy) reflecting periodic recompilation and feature-forking to defeat signature-based detection of earlier PebbleDash variants (Securelist, Kaspersky).
GOMIR / HTTPTROY DERIVATIVES (BirdTroy, DriveTroy) BACKDOOR (LINUX) · CUSTOM · T1102.002
Go-based backdoor family extending Kimsuky's reach to Linux server infrastructure specifically at compromised groupware/software vendors. DriveTroy is Kimsuky's own entry into Google Drive-based C2, using the legitimate cloud API to blend into a groupware server's ordinary traffic profile (Enki WhiteHat, 2026).
GOBEAR / TROLL STEALER STEALER · CUSTOM · T1555 / T1003
Credential and browser-data stealer pairing; Troll Stealer was flagged in 2024/2025 reporting as novel malware actively leveraged by Kimsuky for expanded credential-harvesting operations (SOC Prime; MITRE ATT&CK S1196/S1197).
KGH_SPY SPYWARE SUITE · CUSTOM · T1113 / T1005
Modular spyware suite (info-stealer, keylogger, and additional plugin modules) documented by Cybereason as part of Kimsuky's broader "KGH" toolset targeting reconnaissance and long-term data collection.
XENORAT (KIMSUKY VARIANT) RAT · MODIFIED COTS · T1219
Modified variant of the open-source XenoRAT remote-access trojan, providing full system control for intelligence gathering; delivered via password-protected archives hosted on Dropbox/Daum in the 2025 embassy spear-phishing campaign (Trellix).
MIMIKATZ / PSEXEC DUAL-USE / LOLBIN · COTS · T1003 / T1570
Widely-available credential-dumping and remote-execution utilities used for internal reconnaissance and lateral movement once inside a target network (MITRE ATT&CK G0094 software list).
GITHUB / GOOGLE DRIVE / DROPBOX / DAUM / BLOGSPOT (ABUSED C2 INFRASTRUCTURE) INFRASTRUCTURE · LEGITIMATE PLATFORM ABUSE · T1102.002
Not malware but core infrastructure: legitimate developer and cloud-storage platforms used directly as C2 channels and payload-staging points ("Operation GitPower" for GitHub; DriveTroy for Google Drive), specifically chosen to blend malicious traffic into normal SaaS usage and defeat domain/IP-reputation-based network detection.
OFFLINE LLM STACK (Ollama, GPT4All, Msty) AI TOOLING · CUSTOM DEPLOYMENT OF COTS SOFTWARE · T1588.007
Self-hosted local model runners assembled to give operators LLM-assisted phishing-lure and malware-development capability without routing prompts through external cloud AI platforms, reducing the chance that operational content is visible to those vendors' own abuse-detection systems (The Hacker News, Aug 2026).
07
Indicators of Compromise All IPs and domains defanged
⚠ IOC HANDLING — All IPs and domains in this table are defanged. Reconstruct before use in detection tooling. Reference URLs in Section 13 are NOT defanged.
Type Value / Description Source Date
DOMAINeucie09111[.]myartsonline[.]comSecurelist/KasperskyObserved since late 2020
URLhxxp://eucie09111[.]myartsonline[.]com/0502/v[.]phpSecurelist/KasperskyObserved since late 2020
CVECVE-2024-1708 — ConnectWise ScreenConnect path-traversal, CVSS 8.4, CISA KEV-listed; exploited to deploy ToddlerSharkCISA KEV; SecurityWeek2024
INFRAAttacker-controlled GitHub repositories used as C2 relay in an LNK→PowerShell→AsyncRAT infection chain ("Operation GitPower"); no fixed repo/domain IOC published — monitor for anomalous repository-content polling from endpoint processesThe Hacker NewsAug 2026
INFRAGoogle Drive API endpoints abused as C2 by the DriveTroy Linux backdoor variant targeting groupware-vendor server infrastructureEnki WhiteHat2025–2026
MESSAGEBehavioral pattern: spear-phish impersonating a foreign advisor/embassy contact → embedded QR code → fake conference registration or spoofed Google account login page for credential harvestingFBI IC3 FLASH AC-000001-MWMay–Jun 2025 (advisory issued 2026-01-08)
NOTEComprehensive current IP/domain/hash IOC lists were not published in the open sources reviewed for this compile (2026-09-02), owing to rapid infrastructure rotation and reliance on legitimate cloud/developer platforms as C2. Consult CISA AA20-301A and FBI IC3 FLASH AC-000001-MW directly for their published machine-readable IOC packages.As of 2026-09-02
08
Analyst Assessment
Overall Threat LevelHIGH
Attribution ConfidenceHIGH (unified naming) / MEDIUM (internal org. boundaries)
TrajectoryEscalating sophistication — AI integration, legitimate-platform C2 abuse, supply-chain expansion
Most Dangerous CapabilityAdaptive social engineering fused with legitimate-service C2 that defeats reputation-based network detection
Primary Intel GapSparse, rapidly-stale public IOC data; unresolved Kimsuky/APT43 internal organizational boundary
Ecosystem / Affiliated Groups
Lazarus Group (sibling RGB-linked cluster) Andariel (sibling RGB-linked cluster)

Kimsuky is assessed as a HIGH, not CRITICAL, threat: unlike destructively-oriented actors, its confirmed impact to date is espionage and financial theft rather than physical or operational disruption, and no source reviewed for this compile documents Kimsuky-attributed critical-infrastructure sabotage. What elevates it above a routine espionage actor is persistence and rate of tradecraft evolution — fourteen-plus years of continuous operation against a stable target set, with a demonstrated pattern of adopting new delivery channels (QR codes), new C2 substrates (GitHub, Google Drive), and now AI tooling faster than defenders have generally re-tuned detections to match.

The single most dangerous capability is not any individual malware family but the combination of highly credible, individually-tailored social engineering with C2 infrastructure built on legitimate, trusted platforms. A SOC that alerts on connections to unfamiliar or newly-registered domains will not flag a beacon to github.com or drive.google.com; this forces defenders toward slower, higher-friction behavioral and content-based detection just as the group's AI-assisted lure generation is making its phishing content harder to distinguish from genuine correspondence. The August 2026 offline-LLM-stack finding is a leading indicator worth taking seriously even though its downstream operational impact is not yet independently measured in public reporting.

Competing hypotheses on organizational structure remain genuinely open. Mandiant's APT43 designation and MITRE's single G0094 entry are not fully reconciled in public source material: it is possible that "Kimsuky" is best understood as one team whose mission has broadened over a decade to include self-funding cybercrime, or as an umbrella covering multiple RGB-directed sub-units that share tooling, infrastructure habits, and reporting lineage without being a single continuously-operating team. This assessment would shift toward the latter if future reporting documents simultaneous, geographically-distinct operational tempos inconsistent with a single unified group — evidence not present in current sources. Forward risk trajectory is upward: continued supply-chain pivoting through South Korean software vendors, further legitimate-platform C2 adoption, and operationalized AI tooling together suggest Kimsuky's effective capability is growing faster than its headcount, a pattern consistent with the broader industry concern (echoed in Anthropic's own August 2025 threat-intelligence reporting on North Korean actors' use of AI) that language models are lowering the skill floor required to sustain prolific, well-crafted state-directed operations.

09
Defensive Recommendations
01
Require phishing-resistant MFA (FIDO2/hardware security keys) for all remote access and sensitive-system authentication, replacing SMS/OTP-based factors that AiTM credential-phishing flows can intercept.
Counters: T1566.001/.002, T1056.002
02
Restrict or manage QR-code scanning from corporate-adjacent mobile devices; where feasible, route scanned URLs through the same web-filtering/proxy controls applied to desktop email links rather than treating mobile as an implicitly trusted, unmonitored channel.
Counters: T1204.001 (quishing pivot)
03
Patch and inventory internet-facing RMM/remote-management software, prioritizing CVE-2024-1708 (ConnectWise ScreenConnect) and any other CISA KEV-listed remote-access products in the environment.
Counters: T1190
04
Deploy egress monitoring for anomalous outbound traffic to GitHub raw-content endpoints, Google Drive API hosts, and Dropbox/Daum, correlating unexpected process-to-cloud-service connections rather than relying solely on domain-reputation allowlisting.
Counters: T1102.002, T1567.002
05
Run targeted awareness training for foreign-policy, diplomatic, academic, and think-tank staff specifically on impersonation of known professional contacts and fabricated conference/meeting invitations — the group's most consistent and highest-yield lure pattern.
Counters: T1566.001/.002, T1589
06
Enable PowerShell script-block logging and AMSI on EDR, and alert on BabyShark-consistent script-execution chains (obfuscated PowerShell spawning reconnaissance/staging commands).
Counters: T1059.001
07
Rotate and monitor PAM/VPN credentials on a regular schedule, and alert on anomalous password-change log entries consistent with the credential-harvesting workflow documented in DomainTools' "Kim leak" analysis.
Counters: T1003
08
Vet and continuously monitor third-party groupware/software-vendor access into customer environments; require prompt vendor breach-notification SLAs given Kimsuky's demonstrated pattern of pivoting from vendor compromise into customer credential theft.
Counters: Supply-chain lateral movement (T1190, T1195-adjacent)
10
OPSEC Procedures Observed infrastructure hygiene, rotation patterns, anti-forensics
Infrastructure Rotation [MEDIUM]
Rapid rotation of disposable subdomains crafted to mimic legitimate mail/cloud services (spoofed Google/Yahoo mail login pages); DomainTools' analysis of a leaked operational dataset ("the Kim dump") and CISA AA20-301A both note a pattern of operating significant supporting infrastructure out of Chinese and Russian IP space while targeting South Korea, using regionally-plausible hosting to reduce geolocation suspicion.
Living-off-the-Land Ratio [MEDIUM]
Heavy and growing reliance on legitimate cloud/developer platforms — GitHub, Google Drive, Dropbox, Daum, Blogspot, and VS Code remote tunnels — as C2 and delivery infrastructure rather than bespoke, attacker-registered servers. This blends malicious traffic into normal SaaS/developer usage patterns and specifically defeats network detections tuned to known-bad infrastructure rather than behavioral anomalies.
Anti-Forensics Routines [LOW]
Source material reviewed for this compile does not document specific log-clearing, timestomping, or artifact-removal procedures attributed to Kimsuky. Stated explicitly as a gap rather than inferred from general APT tradecraft assumptions.
Timing & Operational Patterns [LOW]
DomainTools' leaked-dataset analysis suggests a disciplined, systematic operator workflow (structured reconnaissance, PAM password-change logging), but no source reviewed independently confirms a specific work-hours cadence or beacon-jitter configuration relative to victim time zones. Flagged as a gap rather than assumed.
Tooling Hygiene [MEDIUM]
Consistent, deliberate evolution and rebranding of malware families — PebbleDash into HelloDoor/httpMalice/MemLoad/httpTroy; Gomir/HttpTroy into BirdTroy/DriveTroy — indicates recompilation and feature-forking specifically to evade signature-based detection of prior variants. The August 2026 adoption of self-hosted, offline LLMs (Ollama, GPT4All, Msty) for phishing-lure and malware-development assistance is itself a tooling-hygiene decision: keeping AI-assisted development off external cloud AI platforms avoids exposing operational content to those vendors' own abuse-detection and threat-intelligence pipelines.
11
Detection Evasion Specific techniques, LOLBin sequences, EDR bypass patterns
Legitimate-Service C2 Abuse — GitHub T1102.002
NETWORK SIEM
"Operation GitPower" uses attacker-controlled GitHub repositories as a covert C2 channel within an LNK-to-PowerShell infection chain, distributing AsyncRAT payloads disguised as image files; this blends C2 traffic into expected developer/DevOps network activity, defeating domain-reputation- and IP-based network detections tuned to unfamiliar infrastructure.
Chain per public reporting: malicious LNK file → PowerShell downloader stage → AsyncRAT payload masqueraded as an image file (.jpg-style naming), staged and retrieved via GitHub repository content (The Hacker News, Aug 2026). Precise repository-request patterns and full command-line arguments not publicly documented as of 2026-09-02.
Cloud Storage C2 — Google Drive (DriveTroy) T1102.002
NETWORK
The DriveTroy Go-based Linux backdoor variant of the Gomir/HttpTroy family uses the Google Drive API as its C2 channel, specifically chosen to blend into a compromised groupware server's legitimate cloud-API traffic and evade network monitoring tuned to unfamiliar destinations.
Specific Drive API call sequences and authentication-token handling not publicly documented as of 2026-09-02 (Enki WhiteHat's published analysis describes the technique at a behavioral level without full protocol detail).
QR-Code Delivery to Bypass Email Security (Quishing) T1204.001
SIEM NETWORK
Embeds a malicious URL inside a QR code within the phishing email body rather than as a clickable link or attachment, so the victim scans it with a personal/mobile device — moving the malicious request off the monitored corporate endpoint and its email-security/proxy stack entirely.
Documented flow (FBI IC3 FLASH AC-000001-MW, 2026-01-08): spoofed email from a trusted contact → embedded QR code → fake conference-registration landing page → registration button → spoofed Google account login page for credential harvesting.
Remote Access via Legitimate Developer Tooling — VS Code Tunnels T1219 (adjacent)
EDR
Expansion of the toolkit (per May 2026 reporting alongside HTTPSpy and HelloDoor) to abuse Visual Studio Code's built-in remote-tunnel feature — a legitimate, Microsoft-signed capability unlikely to be flagged by EDR application-control policies tuned to block traditional third-party remote-access software.
Specific tunnel-configuration commands and authentication-token acquisition steps not publicly documented as of 2026-09-02.
12
Emulation Resources MITRE CTID & Published Adversary Emulation Plans
MITRE CTID — NOT AVAILABLE No Kimsuky Adversary Emulation Plan Published
The MITRE Center for Threat-Informed Defense's Adversary Emulation Library (github.com/center-for-threat-informed-defense/adversary_emulation_library, checked 2026-09-02) currently contains full emulation plans for APT29, Blind Eagle, Carbanak Group, FIN6, FIN7, menuPass, OceanLotus, OilRig, Sandworm, Turla, and Wizard Spider. No plan for Kimsuky, APT43, THALLIUM, or Velvet Chollima exists in the repository as of this date.
Additional Emulation Resources
GAP
No Kimsuky-specific Atomic Red Team test bundle or SigmaHQ rule set was identified in the sources reviewed for this compile (as of 2026-09-02).
Defenders should rely on the generic ATT&CK-technique-mapped Atomic Red Team tests for the techniques in Section 04 (e.g. T1566, T1059.001, T1053.005, T1003, T1102.002) pending publication of actor-specific detections.
CISA / FBI
Government Advisory · Accessed: 2026-09-02
FBI / IC3
Government Advisory / Detection Guidance · Accessed: 2026-09-02
13
References URLs are NOT defanged — navigate directly
Securelist / Kaspersky
Accessed: 2026-09-02
SecurityWeek
Accessed: 2026-09-02
Center for Threat-Informed Defense
Accessed: 2026-09-02