Brave Prince is a Windows malware family associated with the North Korean threat actor Kimsuky. It has been used in espionage operations targeting South Korean organizations, including think tanks, research institutions, universities, and aerospace-related entities. The malware family has been active since at least 2017 and has appeared in later campaigns as part of modular intrusion chains that overlap with Gold Dragon-derived tooling.
Brave Prince supports host reconnaissance and post-compromise collection. Documented behaviors include enumerating running processes, collecting local network configuration and ARP cache information, and querying the Windows Registry for system and environment details. It also includes defense-evasion functionality through termination of antimalware processes. Variants have been observed exfiltrating collected information through attacker-controlled email accounts and, in later versions, via HTTP POST to attacker infrastructure.
Brave Prince has been linked to Kimsuky operations that used staged delivery chains built around malicious Microsoft Office documents with VBA macros, VBScript downloaders, persistence via Startup-folder shortcuts, and follow-on payload retrieval from attacker-controlled web content. In related deployments, associated modules performed broader reconnaissance, keylogging, credential harvesting, and process injection, indicating Brave Prince’s role within a larger espionage toolkit rather than as a standalone commodity implant. The family is primarily associated with intelligence collection against South Korean policy, geopolitical, and scientific targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes threat actors and malware disabling, stopping, uninstalling, or modifying antivirus, EDR, Windows Defender, AMSI, logging, and other security controls.
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Gathers network configuration details and ARP cache data.
Kimsuky-linked implant family (active since at least 2017) used for espionage; characterized here by mailbox-based exfiltration and code lineage shared with Gold Dragon, with derivatives in this campaign supporting reconnaissance, credential harvesting, and exfiltration workflows orchestrated by scripts.
Backdoor that gathers network configuration details and ARP cache information.
Backdoor malware capable of listing running processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.