North Korea-linked Kimsuky—also tracked as Black Banshee, Thallium, and in some reporting APT37/CloudDragon—has been tied to a broad espionage effort spanning credential theft, malware delivery, and infrastructure compromise. Research correlates multiple malware families including BabyShark, AppleSeed, FlowerPower, GoldDragon, WildCommand, MyDogs, and JamBog, linking them through shared phishing themes, command-and-control patterns, encoding routines, and overlapping infrastructure. The activity targeted South Korea most heavily, while also reaching Japan, U.S. policy and national security organizations, academia, media, defense, finance, and international bodies; separate reporting also described continued targeting of South Korean science, technology, and defense sectors through the actor’s Blue Estimate campaign and newly observed DLL malware and domains.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
On 2020-11-11, ESRC reported new indicators tied to the North Korea-linked Thallium/Kimsuky group's Blue Estimate campaign. The report connected fresh malware, newly observed domains, and reused registrant artifacts to sustained targeting of South Korean science, technology, and defense sectors.
ESRC discovered a new 64-bit DLL sample, ut_zeus(x64).dll, with a build time of 2020-11-10 12:01:08 KST. The malware communicated with app.veryton[.]ml at 216.189.159.36 and was linked to the Blue Estimate campaign.
ESRC observed reconnaissance and intrusion-oriented malicious emails sent on November 4, 2020 as part of the Blue Estimate campaign. The activity targeted South Korean science, technology, and defense-related organizations.
ESRC reports that the domain kaist-ac[.]xyz, later used in the Blue Estimate campaign infrastructure, was created on 2020-11-01. It was registered through Porkbun, which ESRC says had also appeared in another Thallium case.
ESRC says the malware string-encryption flow in the November 2020 sample resembled a Thallium campaign disclosed on 2020-10-16 involving fake cryptocurrency wallet firmware. This anchors an earlier public disclosure tied to the same threat cluster.
PwC UK published a presentation in September 2020 titled "To catch a Banshee: How Kimsuky’s tradecraft betrays its complementary campaigns and mission." The report correlated malware families, C2 infrastructure, phishing domains, and targeting patterns across Kimsuky operations from 2013 to 2020.
The Black Hat presentation describes a supply-chain attack conducted between August 2020 and October 2020 against a Korean cryptocurrency hardware wallet. A modified Windows installer was used to steal user seed and passcode data, and Android users were also implicated through related lures and alerts.
ESRC reports that an earlier 32-bit DLL variant, ut_zeus(x86).dll, was built on 2020-07-10 21:04:00 KST and used eastsea.or[.]kr at 45.13.135.103 as C2. The report links this infrastructure to previously observed Thallium activity.
PwC states that the AppleSeed backdoor had been in use since at least October 2019. The malware used temporary JavaScript files executed via WScript and communicated with C2 using a distinctive encoding routine.
ESRC says Microsoft had previously publicized the Thallium group through a lawsuit filed in late 2019. The reference uses this as prior public attribution context for the actor also known as Kimsuky.
PwC's presentation maps Kimsuky activity across malware, infrastructure, campaigns, and targeting from 2013 through 2020. This establishes the start of the campaign period analyzed in the report.
The Black Hat presentation states that Kaspersky publicly named the Kimsuky threat actor in 2013. This is the earliest explicit historical anchor in the provided references.
ASEC reported that Kimsuky compromised a Windows IIS web server at a Korean construction company and used w3wp.exe to launch PowerShell, download a Meterpreter payload from 45.58.52[.]82, and install Go-based proxy malware likely intended to enable later RDP access. The report attributed the activity to Kimsuky based on reused C2 infrastructure and tradecraft such as regsvr32 execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourceblog.alyac.co.kr
Open sourcevb2020.vblocalhost.com
Open sourcei.blackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.