FPSpy is a Kimsuky-associated malware family used in North Korean cyber espionage operations focused on intelligence collection. It has been identified alongside other Kimsuky tooling such as KLogEXE and is associated with campaigns targeting government, defense, enterprise, heavy industry, and individuals of intelligence interest, particularly in contexts aligned with DPRK collection priorities. FPSpy is characterized in reporting as part of Kimsuky’s intelligence-gathering toolkit rather than financially motivated operations. High-confidence public reporting in the supplied material links FPSpy to Kimsuky but does not provide sufficient corroborated technical detail to more precisely classify its functionality, infection chain, or persistence mechanisms beyond its role in espionage-oriented collection activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FPSpy ... Tools FPSpy, KLogger ... Primary Objective Intelligence gathering
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kimsuky-associated malware used for intelligence gathering and keylogging.
New malware variant attributed in the content to Kimsuky/Sparkling Pisces activity.
New malware variant attributed here to Kimsuky (Sparkling Pisces).
New malware variant attributed in the content to Kimsuky/Sparkling Pisces activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.