Kimsuky is a North Korean state-aligned cyberespionage group primarily focused on South Korean interests, with documented targeting in Japan and the United States. It is also tracked as APT43, Black Banshee, Emerald Sleet, SharpTongue, Sparkling Pisces, Springtail, TA406, TA427, Thallium, and Velvet Chollima. The group conducts spearphishing operations using topical and business-themed lures, commonly delivering malicious Windows shortcut files that present decoy documents while executing scripts and payloads in the background. Kimsuky has targeted personnel associated with the nuclear-power sector, cryptocurrency organizations, groupware developers and their customers, and organizations of strategic interest. Kimsuky operations use PowerShell, VBScript, JavaScript, scheduled tasks, cloud services, and legitimate remote-access software to establish persistence and maintain control. Documented activity includes host and security-product discovery, process discovery, collection and exfiltration of Thunderbird, Outlook, and Gmail data, keylogging, and deployment of malicious browser extensions for webmail surveillance. The group has abused Chrome Remote Desktop and AnyDesk, including using UAC-bypass techniques and concealment of remote-access tooling. It also deletes artifacts, obfuscates scripts, rotates command-and-control infrastructure, and uses cloud-hosted services for command delivery and data exfiltration. In 2026, Kimsuky-linked activity included a trojanized cryptocurrency trading platform that delivered a customized Xeno RAT and used staged, memory-resident payload execution. Kimsuky's dominant mission is espionage, though its cryptocurrency-focused activity reflects an expansion into financially oriented targeting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
58 malware families attributed to this actor across reporting.
53 additional families tracked in Mallory.
15 CVEs this actor has used in observed campaigns. 15 of them exploited in the wild.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
APT28 has used a variety of public exploits, including CVE 2020-0688 ... to gain execution on vulnerable Microsoft Exchange... Dragonfly ... exploited ... CVE-2020-0688 for ... MS Exchange... Kimsuky ... including Microsoft Exchange vulnerability CVE-2020-0688. MuddyWater has exploited the Microsoft Exchange memory corruption vulnerability (CVE-2020-0688). During the SolarWinds Compromise, APT29 exploited CVE-2020-0688 against the Microsoft Exchange Control Panel...
CVE-2024-1708 (CVSS:8.4) is a path traversal vulnerability that can allow an attacker to execute code remotely on the ScreenConnect server. Together, CVE-2024-1709 and CVE-2024-1708 can allow a threat actor to perform remote code execution post authentication.
Two critical vulnerabilities, tracked as CVE-2024-1708 and CVE-2024-1709, were recently addressed in ConnectWise ScreenConnect and have been exploited by many threat actors due to its ease of exploitability. CVE-2024-1709 (CVSS:10) can allow for authentication bypass due to insufficient path filtering.
We also found that most of these files used macros as their infection technique, while only a few of them exploited the CVE-2017-0199 vulnerability, which allows attackers to run malicious code on target systems by embedding malicious links in the docx file.
10 more CVEs tied to this actor tracked in Mallory.
2,764 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware masquerading as a draft on-site inspection evidence document for a national service-management operating system.
Use of malicious QR codes in spear-phishing campaigns against organizations in the United States.
A Kimsuky phishing campaign reportedly disguises malicious content as a seafood-ingredient purchase request, using an LNK file.
Conducting a social-engineering campaign against users in South Korea using a malicious LNK disguised as a legitimate business HWP document. The LNK displays a decoy document while extracting and executing PowerShell and JavaScript payloads, establishing scheduled-task persistence, collecting host reconnaissance, exfiltrating it through Backblaze B2, and retrieving further commands.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.