MailFetch.py is a malware tool associated with the North Korean threat actor Kimsuky. It is identified as one of Kimsuky’s bespoke malware families developed for use in the group’s operations. Publicly available information in this context supports attribution to Kimsuky and indicates that it is part of the actor’s custom tooling ecosystem, but does not provide sufficient high-confidence detail on its internal functionality, infection vector, or specific victimology. Based on the available facts, MailFetch.py should be understood as a custom malware component used operationally by Kimsuky rather than a broadly distributed commodity family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Kimsuky has developed its own unique malware such as MailFetch.py for use in operations.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoors (including backdoored images), packers, C2 protocols, and the creation of infected removable media.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware developed by Kimsuky for operational use.
Unique malware used by Kimsuky (name suggests mail collection).
Unique malware used by Kimsuky.
Custom malware developed by Kimsuky for operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.