BabyShark, also publicly tracked as LATEOP, is a Visual Basic Script (VBS)-based malware family associated with the North Korean threat actor Kimsuky, including activity tracked by some reporting as APT43. It has been used in spear-phishing-driven campaigns and is described as having a multi-stage infection chain. Operators can issue VBS- and PowerShell-based commands on infected systems, and Kimsuky has used BabyShark after initial access together with PowerShell or the Windows command shell for execution.
Reported capabilities include reconnaissance, persistence, data staging and exfiltration support, and cleanup. Observed host discovery behavior includes execution of whoami and ipconfig /all, as well as registry queries against HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default. BabyShark has used scheduled tasks for persistence. For exfiltration preparation, it has encoded data using certutil before exfiltration. Reporting also notes cleanup of files associated with secondary payload execution.
BabyShark is part of Kimsuky’s broader malware arsenal alongside tools such as AppleSeed, GoldDragon, PebbleDash, RandomQuery, KONNI, KimJongRAT, and ReconShark. Multiple reports link BabyShark to KimJongRAT: analysts in 2019 observed ties between BabyShark campaigns using North Korea-themed decoy files and KimJongRAT, including shared data storage paths and co-occurrence during attacker antivirus testing. SentinelLABS described ReconShark as an evolved reconnaissance component of the BabyShark family. Open-source reporting cited in the content states that APT43 activity is widely associated with LATEOP, publicly known as BabyShark. Targeting linked to Kimsuky in the supporting content includes organizations and individuals in South Korea as well as think tanks, research universities, and government-related entities in the United States, Europe, and Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"We have not observed an in-the-wild case yet, but we did find a PHP sample exploiting CVE-2018-8174 (Windows VBScript Engine Remote Code Execution Vulnerability) on the BabyShark C2 server, and this suggests that the threat actor may be leveraging this vulnerability to make a target load BabyShark’s first stage HTA via a watering hole attack or a malicious URL in a spearphishing email."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2019, analysts identified ties between the BabyShark campaign, which used North Korea–themed decoy files, and KimJongRAT. According to Unit 42, BabyShark stored collected data to the same file path as KimJongRAT, and freshly compiled KimJongRAT samples appeared alongside BabyShark during the attacker’s AV testing.
Tools BabyShark, KONNI, FastFire, FireViewer, FastSpy, ReconShark, KimJongRAT, Kimsuky ... Malware families such as Kimsuky RAT, KimJongRAT, KONNI, and BabyShark have been linked to NICKEL KIMBALL activity.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Ongoing campaigns use a new malware component we call ReconShark, which is actively delivered to specifically targeted individuals through spear-phishing emails, OneDrive links leading to document downloads... In the malicious emails, Kimsuky entices the target to open a link to download a password-protected document. Most recently, they made use of Microsoft OneDrive to host the malicious document for download.
Similar to previous BabyShark variants, ReconShark relies on Windows Management Instrumentation (WMI) to query process and battery information.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Most open-source reporting on APT43 tracks the group using LATEOP (known publicly as ‘BabyShark’) ... its activities are much better known for being associated with LATEOP, a backdoor based on VisualBasic scripts.
((source=" WinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode="1") OR (source=" WinEventLog:Security" EventCode="4688") | WHERE (Image LIKE "%reg.exe%" AND ParentImage LIKE "%cmd.exe%")
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
ReconShark functions as a reconnaissance tool... ReconShark checks for the presence of a broad set of processes associated with detection mechanisms, such as ntrtscan.exe, mbam.exe, NortonSecurity.exe, and avpui.exe.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
111 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
43 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware/campaign family discussed as historically linked to KimJongRAT and attributed in the report to Kimsuky.
Malware payload referenced as being delivered after QR-code (“quishing”) spear-phishing; used to establish access after credential harvesting and support follow-on activity (persistence/lateral movement/exfiltration) in the described Kimsuky campaign.
BabyShark is a backdoor malware used by the Kimsuky APT group, recently delivered via the ClickFix campaign.
A named campaign/cluster associated with Kimsuky involving ClickFix-style social engineering and multi-stage scripting to establish persistence, collect system information, and enable remote access; the content also notes a ZIP used to drop BabyShark malware on Windows hosts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.