LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0094: Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

EnterpriseG0094GroupObject v5.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G0094: Kimsuky describes [Kimsuky](https://attack.mitre.org/groups/G0094) is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. [Kimsuky](https://attack.mitr...

Executive priority

G0094: Kimsuky is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G0094: Kimsuky by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G0094: Kimsuky appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Kimsuky

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

70 rows
DomainIDNameRelationship / procedure
EnterpriseT1678Delay Execution

Kimsuky has utilized the Sleep function to ensure execution of scripts.CitationGen Digital Kimsuky HTTPTroy October 2025CitationAryaka Kimsuky July 2025

EnterpriseT1005Data from Local System

Kimsuky has collected Office, PDF, and HWP documents from its victims.[11]CitationTalos Kimsuky Nov 2021 Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.CitationAryaka Kimsuky July 2025

EnterpriseT1587.001MalwareSub-technique

Kimsuky has developed its own unique malware such as MailFetch.py for use in operations.CitationKISA Operation MuzabiCitationTalos Kimsuky Nov 2021[5]

EnterpriseT1583Acquire Infrastructure

Kimsuky has used funds from stolen and laundered cryptocurrency to acquire operational infrastructure.[5]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Kimsuky has used RDP for direct remote point-and-click access.[7]

EnterpriseT1585.002Email AccountsSub-technique

Kimsuky has created email accounts for phishing operations.CitationKISA Operation Muzabi[5][6]

EnterpriseT1566Phishing

Kimsuky has used spearphishing to gain initial access and intelligence.[10][5]

EnterpriseT1685Disable or Modify Tools

Kimsuky has been observed turning off Windows Security Center and can hide the AV software window from the view of the infected user.[11]CitationTalos Kimsuky Nov 2021

EnterpriseT1204.002Malicious FileSub-technique

Kimsuky has used spearphishing attachments to entice victims into opening malicious files, including LNK files disguised with tailored filenames and fake extensions.[13]CitationVirusBulletin Kimsuky October 2019[4][2][3]CitationTalos Kimsuky Nov 2021CitationNaumaanProofpoint_GlobalClickFix_April2025 Kimsuky has also delivered malicious payloads within archive files (e.g., ZIP), which display decoy documents upon execution while running malicious code in the background.CitationGen Digital Kimsuky HTTPTroy October 2025

EnterpriseT1040Network Sniffing

Kimsuky has used the Nirsoft SniffPass network sniffer to obtain passwords sent over non-secure protocols.[4][7]

EnterpriseT1566.002Spearphishing LinkSub-technique

Kimsuky has sent spearphishing emails containing a link to a document that contained malicious macros or took the victim to an actor-controlled domain.[1][7]CitationKISA Operation Muzabi

EnterpriseT1056.003Web Portal CaptureSub-technique

Kimsuky has collected credentials from a fake Google account login page.CitationFBI_KimsukyQR_Jan2026

EnterpriseT1539Steal Web Session Cookie

Kimsuky has used malware, such as TRANSLATEXT, to steal and exfiltrate browser cookies.CitationZscaler Kimsuky TRANSLATEXTCitationS2W Troll Stealer 2024

EnterpriseT1588.002ToolSub-technique

Kimsuky has obtained and used tools such as Nirsoft WebBrowserPassVIew, Mimikatz, and PsExec.[7]CitationTalos Kimsuky Nov 2021[5]

EnterpriseT1078.003Local AccountsSub-technique

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.[7]

EnterpriseT1020Automated Exfiltration

Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.CitationAryaka Kimsuky July 2025

EnterpriseT1140Deobfuscate/Decode Files or Information

Kimsuky has decoded malicious VBScripts using Base64.CitationTalos Kimsuky Nov 2021 Kimsuky has also decoded malicious PowerShell scripts using Base64.CitationSecuronix Kimsuky February 2025CitationAryaka Kimsuky July 2025 Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure.CitationAryaka Kimsuky July 2025

EnterpriseT1204.004Malicious Copy and PasteSub-technique

Kimsuky has leveraged ClickFix type tactics enticing victims to copy and paste malicious code.CitationNaumaanProofpoint_GlobalClickFix_April2025

EnterpriseT1027.010Command ObfuscationSub-technique

Kimsuky has encoded malicious PowerShell scripts using Base64.CitationSecuronix Kimsuky February 2025

EnterpriseT1608.001Upload MalwareSub-technique

Kimsuky has used compromised and acquired infrastructure to host and deliver malware including Blogspot to host beacons, file exfiltrators, and implants.CitationTalos Kimsuky Nov 2021[5] Kimsuky has also hosted malicious payloads on Dropbox.CitationSecuronix Kimsuky February 2025

EnterpriseT1105Ingress Tool Transfer

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.CitationTalos Kimsuky Nov 2021CitationCrowdstrike GTR2020 Mar 2020CitationSecuronix Kimsuky February 2025CitationAryaka Kimsuky July 2025

EnterpriseT1587Develop Capabilities

Kimsuky created and used a mailing toolkit to use in spearphishing attacks.CitationVirusBulletin Kimsuky October 2019

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Kimsuky has exfiltrated stolen files and data to actor-controlled Blogspot accounts.CitationTalos Kimsuky Nov 2021 Kimsuky has also leveraged Dropbox for uploading victim system information.CitationSecuronix Kimsuky February 2025

EnterpriseT1598Phishing for Information

Kimsuky has used tailored spearphishing emails to gather victim information including contat lists to identify additional targets.[5]

EnterpriseT1684.001ImpersonationSub-technique

Kimsuky has also impersonated legitimate people, such as a foreign advisor, an embassy employee, and a think tank employee.CitationFBI_KimsukyQR_Jan2026 Kimsuky has also purported to be a Japanese diplomat to communicate with the victims.CitationNaumaanProofpoint_GlobalClickFix_April2025

EnterpriseT1553.002Code SigningSub-technique

Kimsuky has signed files with the name EGIS CO,. Ltd. and has stolen a valid certificate that is used to sign the malware and the dropper.[13]CitationS2W Troll Stealer 2024

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

Kimsuky has disguised services to appear as benign software or related to operating system functions.[4]CitationSecuronix Kimsuky February 2025

EnterpriseT1115Clipboard Data

Kimsuky has the ability to steal data from the clipboard.CitationAryaka Kimsuky July 2025

EnterpriseT1559.001Component Object ModelSub-technique

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications.CitationGen Digital Kimsuky HTTPTroy October 2025 Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.CitationAryaka Kimsuky July 2025

EnterpriseT1102.002Bidirectional CommunicationSub-technique

Kimsuky has used Blogspot pages and a Github repository for C2.CitationTalos Kimsuky Nov 2021CitationZscaler Kimsuky TRANSLATEXT Kimsuky has also leveraged Dropbox for downloading payloads and uploading victim system information.CitationSecuronix Kimsuky February 2025

EnterpriseT1489Service Stop

Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox.CitationAryaka Kimsuky July 2025

EnterpriseT1217Browser Information Discovery

Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys.CitationAryaka Kimsuky July 2025

EnterpriseT1204.001Malicious LinkSub-technique

Kimsuky has lured victims into clicking malicious links.CitationKISA Operation Muzabi

EnterpriseT1534Internal Spearphishing

Kimsuky has sent internal spearphishing emails for lateral movement after stealing victim information.CitationKISA Operation Muzabi

EnterpriseT1190Exploit Public-Facing Application

Kimsuky has exploited various vulnerabilities for initial access, including Microsoft Exchange vulnerability CVE-2020-0688.CitationKISA Operation Muzabi

EnterpriseT1593.001Social MediaSub-technique

Kimsuky has used Twitter to monitor potential victims and to prepare targeted phishing e-mails.[3]

EnterpriseT1027.007Dynamic API ResolutionSub-technique

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.CitationGen Digital Kimsuky HTTPTroy October 2025

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters.CitationAryaka Kimsuky July 2025 Kimsuky has also encoded files with Base64 and RC4.CitationAryaka Kimsuky July 2025 Kimsuky has utilized XOR and RC4 to encode malicious payloads.CitationGen Digital Kimsuky HTTPTroy October 2025

EnterpriseT1585Establish Accounts

Kimsuky has leveraged stolen PII to create accounts.[5]

EnterpriseT1589.003Employee NamesSub-technique

Kimsuky has collected victim employee name information.CitationKISA Operation Muzabi

EnterpriseT1218.011Rundll32Sub-technique

Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network.CitationTalos Kimsuky Nov 2021CitationAryaka Kimsuky July 2025

EnterpriseT1564.002Hidden UsersSub-technique

Kimsuky has run reg add ‘HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList’ /v to hide a newly created user.CitationKISA Operation Muzabi

EnterpriseT1176.001Browser ExtensionsSub-technique

Kimsuky has used Google Chrome browser extensions to infect victims and to steal passwords and cookies.[14][7]

EnterpriseT1070.004File DeletionSub-technique

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk.[11]CitationTalos Kimsuky Nov 2021CitationKISA Operation Muzabi Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads.CitationSecuronix Kimsuky February 2025 Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.CitationAryaka Kimsuky July 2025

EnterpriseT1219.002Remote Desktop SoftwareSub-technique

Kimsuky has used a modified TeamViewer client as a command and control channel.[11]CitationCrowdstrike GTR2020 Mar 2020

EnterpriseT1583.004ServerSub-technique

Kimsuky has purchased hosting servers with virtual currency and prepaid cards.CitationKISA Operation Muzabi

EnterpriseT1552.004Private KeysSub-technique

Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`.CitationAryaka Kimsuky July 2025

EnterpriseT1620Reflective Code Loading

Kimsuky has used the Invoke-Mimikatz PowerShell script to reflectively load a Mimikatz credential stealing DLL into memory.[5] Kimsuky has also used reflective loading through .NET assembly using `[System.Reflection.Assembly]::Load`.CitationSecuronix Kimsuky February 2025

EnterpriseT1111Multi-Factor Authentication Interception

Kimsuky has used a proprietary tool to intercept one time passwords required for two-factor authentication.CitationKISA Operation Muzabi

EnterpriseT1594Search Victim-Owned Websites

Kimsuky has searched for information on the target company's website.CitationKISA Operation Muzabi

EnterpriseT1059.003Windows Command ShellSub-technique

Kimsuky has executed Windows commands by using `cmd` and running batch scripts.CitationTalos Kimsuky Nov 2021CitationKISA Operation Muzabi Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer.CitationAryaka Kimsuky July 2025 Kimsuky has utilized malicious payloads to create reverse shells within the victim environment.CitationGen Digital Kimsuky HTTPTroy October 2025 Kimsuky has also used batch scripts to eventually run QuasarRAT.CitationNaumaanProofpoint_GlobalClickFix_April2025

EnterpriseT1583.001DomainsSub-technique

Kimsuky has registered domains to spoof targeted organizations and trusted third parties including search engines, web platforms, and cryptocurrency exchanges.[13]CitationZdnet Kimsuky Group September 2020[4][2][3]CitationKISA Operation Muzabi[5]

EnterpriseT1012Query Registry

Kimsuky has obtained specific Registry keys and values on a compromised host.CitationTalos Kimsuky Nov 2021

EnterpriseT1591Gather Victim Org Information

Kimsuky has collected victim organization information including but not limited to organization hierarchy, functions, press releases, and others.CitationKISA Operation Muzabi Kimsuky has also used large language models (LLMs) to gather information about potential targets of interest.[10]

EnterpriseT1071.001Web ProtocolsSub-technique

Kimsuky has used HTTP GET and POST requests for C2.CitationTalos Kimsuky Nov 2021CitationAryaka Kimsuky July 2025

EnterpriseT1585.001Social Media AccountsSub-technique

Kimsuky has created social media accounts to monitor news and security trends as well as potential targets.CitationKISA Operation Muzabi

EnterpriseT1657Financial Theft

Kimsuky has stolen and laundered cryptocurrency to self-fund operations including the acquisition of infrastructure.[5]

EnterpriseT1136.001Local AccountSub-technique

Kimsuky has created accounts with net user.CitationKISA Operation Muzabi

EnterpriseT1007System Service Discovery

Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.CitationTalos Kimsuky Nov 2021

EnterpriseT1568Dynamic Resolution

Kimsuky has used Dynamic DNS (DDNS) services, such as FreeDNS or No-IP DDNS, to include servers located in South Korea.CitationNaumaanProofpoint_GlobalClickFix_April2025

EnterpriseT1027.001Binary PaddingSub-technique

Kimsuky has performed padding of PowerShell command line code with over 100 spaces.CitationSecuronix Kimsuky February 2025

EnterpriseT1586.002Email AccountsSub-technique

Kimsuky has compromised email accounts to send spearphishing e-mails.CitationVirusBulletin Kimsuky October 2019[3]

EnterpriseT1560.003Archive via Custom MethodSub-technique

Kimsuky has used RC4 encryption before exfil.[11]

EnterpriseT1070.006TimestompSub-technique

Kimsuky has manipulated timestamps for creation or compilation dates to defeat anti-forensics.[2]

EnterpriseT1598.003Spearphishing LinkSub-technique

Kimsuky has used links in e-mail to steal account information including web beacons for target profiling.CitationVirusBulletin Kimsuky October 2019[3]CitationKISA Operation Muzabi[6] Kimsuky has also utilized QR codes (also known as Quishing) to direct victims to malicious links through the reliance of a mobile device to scan a code with an embedded malicious URL.CitationEnkiWhiteHat_KimsukyDOCSWAP_Dec2025CitationFBI_KimsukyQR_Jan2026

EnterpriseT1027.012LNK Icon SmugglingSub-technique

Kimsuky has used the LNK icon location to execute malicious scripts.CitationAryaka Kimsuky July 2025 Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script.CitationSecuronix Kimsuky February 2025

EnterpriseT1596Search Open Technical Databases

Kimsuky has used LLMs to better understand publicly reported vulnerabilities.[10]CitationOpenAI-CTI

EnterpriseT1027.016Junk Code InsertionSub-technique

Kimsuky has obfuscated code by filling scripts with junk code and concatenating strings to hamper analysis and detection.CitationSecuronix Kimsuky February 2025

EnterpriseT1550.002Pass the HashSub-technique

Kimsuky has used pass the hash for authentication to remote access software used in C2.[4]

EnterpriseT1557Adversary-in-the-Middle

Kimsuky has used modified versions of PHProxy to examine web traffic between the victim and the accessed website.[4]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S9007: HTTPTroy

HTTPTroy is a highly obfuscated backdoor that facilitates collection, command and control, defense evasion and exfiltration. HTTPTroy was first reported in October 2025. HTTPTroy has been observed in operations attributed to DPRK-affiliated threat actors, including Kimsuky. HTTPTroy has been delivered to victims through a separate loader leveraged by Kimsuky.[1]

Windows
ToolEnterprise

S0111: schtasks

schtasks is used to schedule execution of programs or scripts on a Windows system to run at a specific date and time. [1]

Windows
ToolEnterprise

S0160: certutil

certutil is a command-line utility that can be used to obtain certificate authority information and configure Certificate Services. [1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
5.2
Created
Modified
Raw hash
c8c8e03a7ff7b33b...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.25.2Current bundlec8c8e03a7ff7…
19.15.2Older bundleb37ef7c9ffa9…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    EST Kimsuky April 2019

    Alyac. (2019, April 3). Kimsuky Organization Steals Operation Stealth Power. Retrieved August 13, 2019.

    Open source URL
  2. [2]
    Cybereason Kimsuky November 2020

    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.

    Open source URL
  3. [3]
    Malwarebytes Kimsuky June 2021

    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.

    Open source URL
  4. [4]
    CISA AA20-301A Kimsuky

    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.

    Open source URL
  5. [5]
    Mandiant APT43 March 2024

    Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.

    Open source URL
  6. [6]
    Proofpoint TA427 April 2024

    Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024.

    Open source URL
  7. [7]
    Netscout Stolen Pencil Dec 2018

    ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.

    Open source URL
  8. [8]
    EST Kimsuky SmokeScreen April 2019

    ESTSecurity. (2019, April 17). Analysis of the APT Campaign ‘Smoke Screen’ targeting to Korea and US 출처: https://blog.alyac.co.kr/2243 [이스트시큐리티 알약 블로그]. Retrieved September 29, 2021.

    Open source URL
  9. [9]
    AhnLab Kimsuky Kabar Cobra Feb 2019

    AhnLab. (2019, February 28). Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group. Retrieved September 29, 2021.

    Open source URL
  10. [10]
    MSFT-AI

    Microsoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. Retrieved March 11, 2024.

    Open source URL
  11. [11]
    Securelist Kimsuky Sept 2013

    Tarakanov , D.. (2013, September 11). The “Kimsuky” Operation: A North Korean APT?. Retrieved August 13, 2019.

    Open source URL
  12. [12]
    Symantec Troll Stealer 2024

    Symantec Threat Hunter Team. (2024, May 16). Springtail: New Linux Backdoor Added to Toolkit. Retrieved January 17, 2025.

    Open source URL
  13. [13]
    ThreatConnect Kimsuky September 2020

    ThreatConnect. (2020, September 28). Kimsuky Phishing Operations Putting In Work. Retrieved October 30, 2020.

    Open source URL
  14. [14]
    Zdnet Kimsuky Dec 2018

    Cimpanu, C.. (2018, December 5). Cyber-espionage group uses Chrome extension to infect victims. Retrieved August 26, 2019.

    Open source URL
  15. [15]
    APT43

    (Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024)

  16. [16]
    Black Banshee

    (Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)

  17. [17]
    Cloudflare 2026 Threat Report New Threat Actors March 2026

    Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.

    Open source URL
  18. [18]
    Earth Kumiho

    (Citation: Rapid7 Threat Landscape Actors March 2026)

  19. [19]
    Emerald Sleet

    (Citation: Microsoft Threat Actor Naming July 2023)(Citation: Proofpoint TA427 April 2024)

  20. [20]
    Kimsuky

    (Citation: Securelist Kimsuky Sept 2013)(Citation: Malwarebytes Kimsuky June 2021)

  21. [21]
    Microsoft Threat Actor Naming July 2023

    Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

    Open source URL
  22. [22]
    PatheticSlug

    (Citation: Cloudflare 2026 Threat Report New Threat Actors March 2026)

  23. [23]
    Rapid7 Threat Landscape Actors March 2026

    Rapid7. (2026, March 18). 2026 GLOBAL THREAT LANDSCAPE REPORT: Decoding the Accelerated Cyber Attack Cycle. Retrieved April 18, 2026.

    Open source URL
  24. [24]
    Springtail

    (Citation: Symantec Troll Stealer 2024)

  25. [25]
    TA427

    (Citation: Proofpoint TA427 April 2024)

  26. [26]
    THALLIUM

    (Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024)

  27. [27]
    Velvet Chollima

    (Citation: Zdnet Kimsuky Dec 2018)(Citation: ThreatConnect Kimsuky September 2020)(Citation: Malwarebytes Kimsuky June 2021)

  28. [28]
    mitre-attackG0094
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.