APT Down is a suspected cyber-espionage threat actor assessed to collaborate with the North Korean Kimsuky group. Reporting links the actor to operations targeting South Korean government agencies, military institutions, and telecommunications organizations, with additional activity directed at organizations in Japan and Taiwan. The actor has been described as Chinese-speaking and operating in a structured, corporate-like manner with regular weekday working hours. Observed tradecraft includes phishing and credential-harvesting activity, including impersonation of widely used South Korean online services, as well as exploitation of edge and enterprise products such as Ivanti, Sophos, JBoss/WildFly, and Palo Alto technologies. Tooling associated with the actor includes the Syslogk rootkit, the TinyShell backdoor, and Cobalt Strike Beacon, indicating capabilities spanning initial access, persistence, post-exploitation, defense evasion, and command-and-control-enabled intrusion operations. Reported activity also includes vulnerability scanning and follow-on compromise of exposed systems. APT Down appears primarily focused on intelligence collection against public-sector and strategic targets in East Asia. Although some reporting tags the activity alongside clusters such as APT31, APT41, UNC3886, and UNC5221, those labels should be treated as associations in reporting rather than confirmed aliases based on the available facts. The strongest supported relationship is collaboration with Kimsuky.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.