LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.CitationEST Kimsuky April 2019CitationCybereason Kimsuky November 2020CitationMalwarebytes Kimsuky June 2021CitationCISA AA20-301A KimsukyCitationMandiant APT43 March 2024CitationProofpoint TA427 April 2024

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).CitationNetscout Stolen Pencil Dec 2018CitationEST Kimsuky SmokeScreen April 2019CitationAhnLab Kimsuky Kabar Cobra Feb 2019 In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.CitationMSFT-AI

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

EnterpriseG0094GroupObject v5.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Kimsuky matters because MITRE describes it as a DPRK-based cyber espionage group with long-running collection interests around Korean Peninsula policy, nuclear policy, sanctions, and related government, academic, business services, manufacturing, and international organization targets. For leaders, this is less about a single malware family and more about whether the organization can detect credential theft, remote access tooling, data collection, and abuse of legitimate administration utilities across Windows, Linux, macOS, Android, and browser-adjacent activity where those assets exist.

Executive priority

Prioritize this as an intelligence-led readiness issue for organizations connected to government, policy, education, manufacturing, business services, sanctions, nuclear policy, or Korea-related work. Executive questions should focus on: whether sensitive research and policy data is mapped and monitored; whether identity protections can withstand credential dumping and remote access abuse; whether SOC coverage includes legitimate tools such as PsExec, schtasks, and certutil; and whether incident response plans account for espionage-driven dwell time rather than only disruptive events. The Korea Hydro & Nuclear Power Co. reference also makes this relevant to organizations with cyber-physical or critical infrastructure dependencies, while still requiring local evidence before assuming operational technology exposure.

Technical view

MITRE does not provide a dedicated detection section for this group, so coverage should be built from the relationships. Kimsuky is linked to credential access via LSASS Memory, local data collection, system service discovery, remote access/backdoor tooling, information stealers, downloaders, and legitimate utilities including Mimikatz, PsExec, schtasks, and certutil. SOC and IR teams should validate detections for credential dumping attempts, suspicious service or scheduled task activity, anomalous remote execution, unexpected certificate utility usage, RAT/backdoor network behavior, browser extension masquerading, and Linux/Android visibility where related malware platforms are in scope.

Likely telemetry

  • Endpoint process creation and command-line logs for Windows, Linux, and macOS where available
  • Windows security, EDR, and memory-access telemetry related to LSASS access or credential dumping behavior
  • Service creation, remote execution, and administrative tool usage logs, especially around PsExec-like activity
  • Scheduled task creation and modification telemetry, including schtasks usage
  • certutil execution, file download, certificate-related command activity, and associated network connections

Detection direction

  • Treat the ATT&CK group page as threat-intelligence context, not a complete detection package; MITRE provides no official detection text for this object.
  • Map detections to the related techniques and software: LSASS access, local data discovery, service discovery, remote execution, scheduled tasks, certutil abuse, RAT activity, downloaders, and information stealers.
  • Tune carefully for dual-use tools. PsExec, schtasks, and certutil have legitimate administrative uses, so detections should incorporate user role, host criticality, parent process, command-line arguments, execution timing, destination, and change-control context.
  • Validate visibility beyond Windows. The relationship set includes Windows-heavy tooling but also macOS, Linux, and Android platform references through related software; organizations should confirm whether those environments are monitored rather than assuming Windows-only coverage is sufficient.
  • Use alias handling in threat intelligence workflows. The supplied aliases include Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, and PatheticSlug; reporting overlap can affect alert enrichment, case correlation, and executive briefings.

Mitigation priorities

  • Start with identity and credential protections: reduce administrative exposure, limit credential material available on endpoints, and prioritize controls that reduce or detect LSASS access.
  • Harden and monitor legitimate administration paths, including remote execution, service management, scheduled tasks, and certificate utilities, with clear baselines for approved administrative behavior.
  • Apply application control, script control, and endpoint protection policies to reduce execution of unapproved RATs, downloaders, stealers, and masqueraded installers or extensions.
  • Strengthen data protection around sensitive policy, research, sanctions, manufacturing, and government-related information through access review, logging, and data location awareness.
  • Review browser extension governance and endpoint configuration where extension masquerading is a realistic path for the organization.
Additional notes and limits

This take is based on MITRE ATT&CK G0094 Kimsuky, its official description, aliases, external references, and supplied relationships to software and techniques. The relationship set is especially useful for defensive planning because it shows a mix of credential access, discovery, collection, legitimate tool abuse, remote access malware, stealers, and platform breadth. The Stolen Pencil revoked-by relationship should be handled as historical consolidation context rather than a separate current group assumption.

The object does not specify platforms or tactics at the group level and provides no official detection guidance. Some related descriptions are truncated in the supplied data. Local asset inventory, business relevance to the stated target themes, and available telemetry are required before concluding exposure, coverage, or incident likelihood.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.CitationEST Kimsuky April 2019CitationCybereason Kimsuky November 2020CitationMalwarebytes Kimsuky June 2021CitationCISA AA20-301A KimsukyCitationMandiant APT43 March 2024CitationProofpoint TA427 April 2024

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).CitationNetscout Stolen Pencil Dec 2018CitationEST Kimsuky SmokeScreen April 2019CitationAhnLab Kimsuky Kabar Cobra Feb 2019 In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.CitationMSFT-AI

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
5.2
Created
Modified
Raw hash
b37ef7c9ffa98954...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.