Kimsuky
0
linked CVEs
Also known as
Velvet ChollimaBlack BansheeThalliumOperation Stolen PencilG0086APT43Emerald SleetSpringtailSparkling PiscesTA427Earth KumihoPatheticSlug
Targeted industries
Research - InnovationEnergyDefenseDiplomacyAcademia - University News - Media
Targeted regions
Japan
This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
Source: misp_galaxy · Collected: 2026-08-12
⚡ Vulnerabilities & Exploits0 CVEs
threat_actor_cve → cves / exploits.cve_ids
No CVE correlation on record for this actor yet.
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used130 techniques
Across 15 tactics
Collection12 techniques
T1005Data from Local System
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to…
T1056.001Keylogging
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](ht…
T1056.003Web Portal Capture
Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login…
T1074.001Local Data Staging
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such…
T1113Screen Capture
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access too…
T1114.002Remote Email Collection
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact directly with the Exchange serve…
T1114.003Email Forwarding Rule
Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal information, and further gain i…
T1115Clipboard Data
Adversaries may collect data stored in the clipboard from users copying information within or between applications.
For example, on Windows adversaries can access clipboard data by using <code>clip.…
T1185Browser Session Hijacking
Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser…
T1557Adversary-in-the-Middle
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https:/…
T1560.001Archive via Utility
Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that…
T1560.003Archive via Custom Method
An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods, such as encryption with XOR or stream ci…
Command And Control10 techniques
T1071.001Web Protocols
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and…
T1071.002File Transfer Protocols
Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic. Commands to the remote syste…
T1071.003Mail Protocols
Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic. Commands to the remote…
T1102.001Dead Drop Resolver
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead dr…
T1102.002Bidirectional Communication
Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel. Compromised systems may…
T1105Ingress Tool Transfer
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network th…
T1132.002Non-Standard Encoding
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded us…
T1205Traffic Signaling
Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling involves the use of a magic value or sequence t…
T1219.002Remote Desktop Software
An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interf…
T1568Dynamic Resolution
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common algorith…
Credential Access10 techniques
T1003.001LSASS Memory
Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS). After a user logs on, the system generates and stores a va…
T1040Network Sniffing
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network int…
T1056.001Keylogging
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when [OS Credential Dumping](ht…
T1056.003Web Portal Capture
Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login…
T1111Multi-Factor Authentication Interception
Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network…
T1539Steal Web Session Cookie
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applica…
T1552.001Credentials In Files
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credenti…
T1552.004Private Keys
Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/d…
T1555.003Credentials from Web Browsers
Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web browsers commonly save credentials such as website us…
T1557Adversary-in-the-Middle
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https:/…
Defense Impairment4 techniques
T1112Modify Registry
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Access to specific areas of the Registry depends on…
T1553.002Code Signing
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the b…
T1685Disable or Modify Tools
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensor…
T1686Disable or Modify System Firewall
Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can tamper with f…
Discovery13 techniques
T1007System Service Discovery
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</c…
T1012Query Registry
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
The Registry contains a significant amount of information about the o…
T1016System Network Configuration Discovery
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several opera…
T1033System Owner/User Discovery
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example,…
T1040Network Sniffing
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network int…
T1057Process Discovery
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within th…
T1082System Information Discovery
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this informatio…
T1083File and Directory Discovery
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [F…
T1124System Time Discovery
An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or <code>sys…
T1217Browser Information Discovery
Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of pe…
T1497.001System Checks
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifa…
T1518.001Security Software Discovery
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as cl…
T1680Local Storage Discovery
Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to…
Execution11 techniques
T1053.005Scheduled Task
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The […
T1059.001PowerShell
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system.(Cit…
T1059.003Windows Command Shell
Adversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows…
T1059.005Visual Basic
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as [Component Object Model](https://a…
T1059.006Python
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactiv…
T1059.007JavaScript
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scri…
T1106Native API
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, suc…
T1204.001Malicious Link
An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that will lead to code execution. Th…
T1204.002Malicious File
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This us…
T1204.004Malicious Copy and Paste
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a [Command and Scri…
T1559.001Component Object Model
Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native Windows application programming interface (AP…
Exfiltration3 techniques
T1020Automated Exfiltration
Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020)
When automated exfil…
T1041Exfiltration Over C2 Channel
Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control…
T1567.002Exfiltration to Cloud Storage
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a…
Impact2 techniques
T1489Service Stop
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or ai…
T1657Financial Theft
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of t…
Initial Access6 techniques
T1078.003Local Accounts
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an o…
T1133External Remote Services
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect t…
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfigur…
T1566Phishing
Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spe…
T1566.001Spearphishing Attachment
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing att…
T1566.002Spearphishing Link
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from o…
Lateral Movement3 techniques
T1021.001Remote Desktop Protocol
Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on…
T1534Internal Spearphishing
After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the s…
T1550.002Pass the Hash
Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a us…
Persistence12 techniques
T1053.005Scheduled Task
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The […
T1078.003Local Accounts
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an o…
T1098.007Additional Local or Domain Groups
An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.
On Windows, accounts may use the `net localgroup` and `n…
T1112Modify Registry
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Access to specific areas of the Registry depends on…
T1133External Remote Services
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect t…
T1136.001Local Account
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on…
T1176.001Browser Extensions
Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize aspects…
T1205Traffic Signaling
Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling involves the use of a magic value or sequence t…
T1505.003Web Shell
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to a…
T1543.003Windows Service
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perfor…
T1546.001Change Default File Association
Adversaries may establish persistence by executing malicious content triggered by a file type association. When a file is opened, the default program used to open the file (also called the file associ…
T1547.001Registry Run Keys / Startup Folder
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause th…
Privilege Escalation9 techniques
T1053.005Scheduled Task
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The […
T1055Process Injection
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address spa…
T1055.001Dynamic-link Library Injection
Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges. DLL injection is a method of executing arbitrary co…
T1055.012Process Hollowing
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of…
T1078.003Local Accounts
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an o…
T1098.007Additional Local or Domain Groups
An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.
On Windows, accounts may use the `net localgroup` and `n…
T1543.003Windows Service
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perfor…
T1546.001Change Default File Association
Adversaries may establish persistence by executing malicious content triggered by a file type association. When a file is opened, the default program used to open the file (also called the file associ…
T1547.001Registry Run Keys / Startup Folder
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause th…
Reconnaissance10 techniques
T1589.002Email Addresses
Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing email infrastructure and addresses for employees.
Adve…
T1589.003Employee Names
Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believ…
T1591Gather Victim Org Information
Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of divisio…
T1593.001Social Media
Adversaries may search social media for information about victims that can be used during targeting. Social media sites may contain various information about a victim organization, such as business an…
T1593.002Search Engines
Adversaries may use search engines to collect information about victims that can be used during targeting. Search engine services typical crawl online sites to index context and may provide users with…
T1594Search Victim-Owned Websites
Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of details, including names of departments/divisions,…
T1596Search Open Technical Databases
Adversaries may search freely available technical databases for information about victims that can be used during targeting. Information about victims may be available in online databases and reposito…
T1598Phishing for Information
Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information, frequently…
T1598.003Spearphishing Link
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to trick targets into d…
T1682Query Public AI Services
Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or databas…
Resource Development15 techniques
T1583Acquire Infrastructure
Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure…
T1583.001Domains
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be purchased or, in some cases, acquir…
T1583.004Server
Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise ac…
T1583.006Web Services
Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a web-based service that can be abused during later sta…
T1584.001Domains
Adversaries may hijack domains and/or subdomains that can be used during targeting. Domain registration hijacking is the act of changing the registration of a domain name without the permission of the…
T1585Establish Accounts
Adversaries may create and cultivate accounts with services that can be used during targeting. Adversaries can create accounts that can be used to build a persona to further operations. Persona develo…
T1585.001Social Media Accounts
Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used to build a persona to further operations. Pe…
T1585.002Email Accounts
Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their operations, such as leveraging them to conduct [Phis…
T1586.002Email Accounts
Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct [Phishing fo…
T1587Develop Capabilities
Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities in-house. Thi…
T1587.001Malware
Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of payloads, droppers, post-compromise tools, backdoor…
T1588.002Tool
Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool can be used for malicious purposes by an advers…
T1588.003Code Signing Certificates
Adversaries may buy and/or steal code signing certificates that can be used during targeting. Code signing is the process of digitally signing executables and scripts to confirm the software author an…
T1588.005Exploits
Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or unanticipated behavior to occur…
T1608.001Upload Malware
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, b…
Stealth31 techniques
T1027Obfuscated Files or Information
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavi…
T1027.001Binary Padding
Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This can be done without affecting the functionality or behavior of a binary, but can increase the…
T1027.002Software Packing
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable ch…
T1027.007Dynamic API Resolution
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis. Malware commonly uses various [Nat…
T1027.010Command Obfuscation
Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signat…
T1027.012LNK Icon Smuggling
Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files. Windows shortcut files (.LNK) include many…
T1027.013Encrypted/Encoded File
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within…
T1027.015Compression
Adversaries may use compression to obfuscate their payloads or files. Compressed file formats such as ZIP, gzip, 7z, and RAR can compress and archive multiple files together to make it easier and fast…
T1027.016Junk Code Insertion
Adversaries may use junk code / dead code to obfuscate a malware’s functionality. Junk code is code that either does not execute, or if it does execute, does not change the functionality of the code.…
T1036.004Masquerade Task or Service
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/…
T1036.005Match Legitimate Resource Name or Location
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation…
T1036.007Double File Extension
Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that may cause only the first extension…
T1055Process Injection
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address spa…
T1055.001Dynamic-link Library Injection
Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges. DLL injection is a method of executing arbitrary co…
T1055.012Process Hollowing
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing is a method of executing arbitrary code in the address space of…
T1070.004File Deletion
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: [Ingress Tool Transfe…
T1070.006Timestomp
Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change t…
T1078.003Local Accounts
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an o…
T1140Deobfuscate/Decode Files or Information
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deob…
T1205Traffic Signaling
Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling involves the use of a magic value or sequence t…
T1218.005Mshta
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are several examples of different types of threats levera…
T1218.010Regsvr32
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic…
T1218.011Rundll32
Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://attack.mitre.org/techniques/T1129)), may avoid trigg…
T1480.002Mutual Exclusion
Adversaries may constrain execution or actions based on the presence of a mutex associated with malware. A mutex is a locking mechanism used to synchronize access to a resource. Only one thread or pro…
T1497.001System Checks
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifa…
T1564.002Hidden Users
Adversaries may use hidden users to hide the presence of user accounts they create or modify. Administrators may want to hide users when there are many user accounts on a given system or if they want…
T1564.003Hidden Window
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation ca…
T1564.011Ignore Process Interrupts
Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals. Many operating systems use signals to deliver messages to control process behavior. Command i…
T1620Reflective Code Loading
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory…
T1678Delay Execution
Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in wi…
T1684.001Impersonation
Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims…
🛰️ Infrastructure & IOCs172
| md5 | 30d5f17d5e3f85be18220a7cab0b9fff | — | 2026-08-10 |
| sha256 | b50422ec3a98d098bb3f7d728012da7e1795221c8b0624562568dff87ab5de2a | — | 2026-08-10 |
| sha256 | a40a61e54be9cc1671ea6832fef8139ce811a7d759058bb8b4ca86863f4cc1bd | — | 2026-08-10 |
| sha256 | 5b1f75205cb79a8c8a3d8083f34b552852dfd567dd65763183b7536a29f55f5b | — | 2026-08-10 |
| sha256 | 4d37b4ccd6e4c0c9de82e66e40dfb6412b92ea33bcf10442a290b0732eeadae0 | — | 2026-08-10 |
| sha256 | 456ed6926b706c203ac65b5174ac2ce78a5dad2ef0f083ae1f0aedd75d811ca2 | — | 2026-08-10 |
| sha256 | 0432ae814945633b605c77d137bef96c7f84934c682aada69baa326dce781286 | — | 2026-08-10 |
| sha256 | 018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a898cd | — | 2026-08-10 |
| sha1 | ff6eac85bb9b11d7c1422938235896c8b3a6da3c | — | 2026-08-10 |
| sha1 | feaad17999c1a7c768c6d841e790b2f2c006b00f | — | 2026-08-10 |
| sha1 | beb0ab87b52a417912e0ec84cfa203fd05cae660 | — | 2026-08-10 |
| sha1 | b9f25b21eccbcca77adb11a0e613d4eca4e38442 | — | 2026-08-10 |
| sha1 | a1b44d94af77705b075e67b40eb1937cedc55fa8 | — | 2026-08-10 |
| sha1 | 984a98b7daeee159ea018a055b86a596c5dccc46 | — | 2026-08-10 |
| sha1 | 79fcc73e1bcb0b339336c81c8d733bf00bac4001 | — | 2026-08-10 |
| sha1 | 75ea9f4a55575f39e38c1beb9ec44c0fc7b1c937 | — | 2026-08-10 |
| sha1 | 7117859ffe0380d6e5e6f9691d6d5f5fc1da20d1 | — | 2026-08-10 |
| sha1 | 6bd211981540cd167615e916847e383c5ddb4fbd | — | 2026-08-10 |
| sha1 | 2b381a3f3e303da8832c8b60120aa6f7486264bf | — | 2026-08-10 |
| sha1 | 263efd45e5cedce553c25cf2c49dbcf28c352cd8 | — | 2026-08-10 |
| sha1 | 215343916d101c6bbe287871816e063c78103dd1 | — | 2026-08-10 |
| ip | 27.102.137.159 | — | 2026-08-10 |
| md5 | f73e07efb8707e3561e9cbff74557acb | — | 2026-08-10 |
| md5 | f4e7ca8c1de252840c1f0e957cd4b717 | — | 2026-08-10 |
| md5 | ed2f8dd9b96d706d833b7aa545b8e621 | — | 2026-08-10 |
| md5 | ead95793528572e7b89679860e2f2116 | — | 2026-08-10 |
| md5 | e22367800e9d39bc865bd50cddd0537d | — | 2026-08-10 |
| md5 | e0e4aec6d494fe68cdaa52d6878a8366 | — | 2026-08-10 |
| md5 | ca0b57807f79f26e7f59cab2a2542da0 | — | 2026-08-10 |
| md5 | c7723bf166ef08ff3112257a1244f584 | — | 2026-08-10 |
| md5 | c63d021de798034cbf933e1c99bcb83f | — | 2026-08-10 |
| md5 | c410055bfa198937825dfd7e41000e7a | — | 2026-08-10 |
| md5 | bbf1b0ab9fc27439de4386ed7b8fc151 | — | 2026-08-10 |
| md5 | ba8e682a72c6a3e634c070f0fb057bf5 | — | 2026-08-10 |
| md5 | ba0238423b5c29667cd760ccd7b000aa | — | 2026-08-10 |
| md5 | b516ec6c6b37618ad65080a063270ea4 | — | 2026-08-10 |
| md5 | b50dad56d891ef230656b37ce62cdada | — | 2026-08-10 |
| md5 | b406ea5b8628cb7801f47c0189b96182 | — | 2026-08-10 |
| md5 | af3fa7f22f6e97901f20326cc12bdb49 | — | 2026-08-10 |
| md5 | a5701848f82c65a55765dc534111899f | — | 2026-08-10 |
| md5 | a435292106026e257789036a70ee1a14 | — | 2026-08-10 |
| md5 | a343d8bcf02a0554fa271452a512f3ce | — | 2026-08-10 |
| md5 | a1c07ac866fb6b388e38c6bb1d4bbe94 | — | 2026-08-10 |
| md5 | 8c859a03814443c6f0da341ee594c352 | — | 2026-08-10 |
| md5 | 8406075af0a1e9ec09bafdc0de01f138 | — | 2026-08-10 |
| md5 | 7f12fa589f56f6203c692715b3958d30 | — | 2026-08-10 |
| md5 | 73ff669fc282653bd6c42cf87ade9337 | — | 2026-08-10 |
| md5 | 6add815cd61d6514f81a23ab8c23405a | — | 2026-08-10 |
| md5 | 5c5672bb14e1d2f07a8318ffec19b213 | — | 2026-08-10 |
| md5 | 5af95590a33b9bc64d95808f1fc71b78 | — | 2026-08-10 |
| md5 | 5577fffb5b5acd3771ef9dc696498f1e | — | 2026-08-10 |
| md5 | 4d87fef16790cbe1df72007d99149665 | — | 2026-08-10 |
| md5 | 49bdbe7e6cbb88842afcce3a9fe60e9b | — | 2026-08-10 |
| md5 | 422a221851ea6ad15f53cd3aea51c8af | — | 2026-08-10 |
| md5 | 3e2110d233d4543830e14c78d53900f4 | — | 2026-08-10 |
| md5 | 3b9d40f3d620ec87960b4350d42ccc03 | — | 2026-08-10 |
| md5 | 37cec428257cd41153cf43d7f1a12652 | — | 2026-08-10 |
| md5 | 30792a0c0dfad55fb2b19d3e30e9a7d4 | — | 2026-08-10 |
| md5 | 302725413076d1aeaee2d7f2b3692646 | — | 2026-08-10 |
| md5 | 2eb77109cce1e8afca6245c2963e52a6 | — | 2026-08-10 |
| md5 | 2e76d5316663a3dc472398b1c01cb9a8 | — | 2026-08-10 |
| md5 | 2ab3df4762fbde5d86e99a1ad147850e | — | 2026-08-10 |
| md5 | 2669731cb5ff664dfb5fbfc37637876d | — | 2026-08-10 |
| md5 | 1f378c0efc13669dada1fe340c6837bd | — | 2026-08-10 |
| md5 | 0d8ceb7dea7d471afa2f8e753b13d2d6 | — | 2026-08-10 |
| md5 | 02ebc2356f9f700bbdac444cdefa0da2 | — | 2026-08-10 |
| sha256 | 7bc61d1bbc90d66d9988fd3baacd7834b1d2dfefe6d4ac999a194bccb9ba7dfc | — | 2026-08-10 |
| sha256 | e34d73a1da492c9a79a9729f2f7d9d4b5a2448f44934bd5552bd0bbbe1586767 | — | 2026-08-10 |
| ip | 27.102.138.44 | — | 2026-08-10 |
| sha256 | 9be8f2be7ad882e8423c269a0540b7c73d6470311ddfcfcd318ff9d1983e2935 | — | 2026-08-10 |
| sha256 | 4b0358c7e4afa54bc489a6199cca132b5f4a330892eb15bf06c0c4da9e020df2 | — | 2026-08-10 |
| sha1 | 5746f3e78351439caebfa3721e8feea36b67263f | — | 2026-08-10 |
| md5 | aa9d5dd632bb90addca480eaa5ff4382 | — | 2026-08-10 |
| sha256 | 4453b9e985f452365995c399f5292c92764570f03e6a066d7845320dd4ad09a1 | — | 2026-08-10 |
| sha256 | 22180919f562fb9f6e50d7f20b2eb3f94eb009c212b74b45cf77659fe8274d5b | — | 2026-08-10 |
| ip | 27.102.137.126 | — | 2026-08-10 |
| ip | 112.216.9.171 | — | 2026-08-10 |
| sha256 | a4f72ce8b5736fe3ca2083cfe21bd51697f12e900e307c357cb8523b8f86e3ec | — | 2026-08-10 |
| sha256 | 9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470 | — | 2026-07-25 |
| domain | lutkdd.corpsecs.com | — | 2026-07-25 |
| domain | pxqtkc.corpsecs.com | — | 2026-07-25 |
| sha256 | 221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9 | — | 2026-07-25 |
| url | http://googleoba.servequake.com:8443/agent.ashx | — | 2026-07-25 |
| domain | googleoba.servequake.com | — | 2026-07-25 |
| url | https://lutkdd.corpsecs.com | — | 2026-07-25 |
| sha256 | 107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21 | — | 2026-07-25 |
| sha256 | e4ccb2328c06710a7f0254cb6315e1b106396b0ff525f9cf3eada6e85d285c1c | — | 2026-07-25 |
| url | https://pxqtkc.corpsecs.com | — | 2026-07-25 |
| md5 | 0b1de625a89da12bd1fdd292b341bad3 | — | 2026-07-24 |
| domain | bohyeonsanvil.com | — | 2026-07-24 |
| domain | kumhosports.com | — | 2026-07-24 |
| md5 | 07bb21d28ae4ab07d62f8deb4343aaeb | — | 2026-07-24 |
| md5 | 05c07339603994b36dcfefcce720d03d | — | 2026-07-24 |
| md5 | 03e4bef86f3e3e6ea23eb6f017af0c98 | — | 2026-07-24 |
| md5 | 07ed2c9ed61b60078af0164f061696be | — | 2026-07-24 |
| url | https://global.webjine.o-r.kr/index.php | — | 2026-07-21 |
| url | https://commit.hanbiro.o-r.kr/index.php | — | 2026-07-21 |
| url | https://auth.samecloud.o-r.kr/index.php | — | 2026-07-21 |
| url | http://www.ilskdeid.o-r.kr:8000 | — | 2026-07-21 |
| url | http://auth.samecloud.o-r.kr/index.php | — | 2026-07-21 |
| ip | 69.10.50.165 | — | 2026-07-21 |
| ip | 163.245.195.172 | — | 2026-07-21 |
| sha256 | 073d9dd98a9ca3cd03901c31ba57811a1632e316923022640670ce00622cd8a9 | — | 2026-07-21 |
| sha256 | 01b1c767f62e48efeb86410fd014fed4295ccb084bfcd6d5b9197638b615a648 | — | 2026-07-21 |
| sha1 | f3ed0bcc692555fea83c6556abaa5dc2b91bcb38 | — | 2026-07-21 |
| sha1 | 3fb6111490cac9f5c4b34f9fed459f01c10d2314 | — | 2026-07-21 |
| md5 | e911f8f7c49476806ada37f3ebb7a28a | — | 2026-07-21 |
| md5 | e6c6fa32da47d9341b778bfa424abb4c | — | 2026-07-21 |
| md5 | dff787bce68c7653495f153c0534cb96 | — | 2026-07-21 |
| md5 | ca98a51cebdc802d255030b4baa44ca0 | — | 2026-07-21 |
| md5 | c2e37232556357944a04edf1dec3934b | — | 2026-07-21 |
| md5 | bf215181b5140522137b3d4f6b73544a | — | 2026-07-21 |
| md5 | b1c72139f2cdd9419562369fc6ced4fc | — | 2026-07-21 |
| md5 | aa61e76255a6e13313439655bc02bdf5 | — | 2026-07-21 |
| md5 | a452a860f973c7a43ea804c17e9427d2 | — | 2026-07-21 |
| md5 | 84e9b066bebd49036b7fc71b5f5f8d83 | — | 2026-07-21 |
| domain | node896147.dwservice.net | — | 2026-07-21 |
| domain | node828765.dwservice.net | — | 2026-07-21 |
| url | https://www.dwservice.net | — | 2026-07-21 |
| domain | commit.hanbiro.o-r.kr | — | 2026-07-21 |
| domain | oobe.webjine.o-r.kr | — | 2026-07-21 |
| domain | www.ilskdeid.o-r.kr | — | 2026-07-21 |
| domain | oauth.shacloud.o-r.kr | — | 2026-07-21 |
| domain | node449013.dwservice.net | — | 2026-07-21 |
| domain | global.webjine.o-r.kr | — | 2026-07-21 |
| domain | auth.samecloud.o-r.kr | — | 2026-07-21 |
| url | https://oobe.webjine.o-r.kr/index.php | — | 2026-07-21 |
| url | https://oauth.shacloud.o-r.kr:8443 | — | 2026-07-21 |
| sha256 | 4a3e9f6b214effe5028a0bf36776190916621fd7977bf3720cb6ead34d9ee20d | — | 2025-08-18 |
| sha256 | 48fe8b7c8ceb1575dcdb6cf9f717d322e3450b2a06d6fab3d05ca907048aa1cd | — | 2025-08-18 |
| domain | bp.nidnaver.cloud | — | 2025-08-18 |
| md5 | 45bd30d3a52904a7fe64fd97c31e3a1c | — | 2025-08-18 |
| md5 | 488570af25f908e907c9732aae632b0f | — | 2025-08-18 |
| md5 | 25595588106848b2054497ceba1a2d66 | — | 2025-08-18 |
| sha256 | 1e10203174fb1fcfb47bb00cac2fe6ffe660660839b7a2f53d8c0892845b0029 | — | 2025-08-18 |
| sha256 | 18ab9a5bd68314b8a91070f18ca9c2c9097a3441b058edccd304b0e33d6c1422 | — | 2025-08-18 |
| md5 | 0e0f720193204cbd1a2c847d76f9e82f | — | 2025-08-18 |
| md5 | 02430604d146e8e33554061344ca806e | — | 2025-08-18 |
| url | https://dl.dropboxusercontent.com/scl/fi/c6ba7iwuke57d75j3mmte/eula.rtf?rlkey=t0jnirhxk48xdu8p74rqgv9dw&st=oofgjsq8&dl=0 | — | 2025-08-18 |
| url | https://dl.dropbox.com/scl/fi/sb19vsslj13wdkndskwuou/eula.rtf?rlkey=axrb5o5mv14afu7g6e8s3d5s8&st=xy96nggc&dl=0 | — | 2025-08-18 |
| url | https://dl.dropbox.com/scl/fi/kpxdthefmdbxw9m31tao3/krumhan.rtf?rlkey=yhzti914uzn72wm4iruej24px&st=xjzyd4ip&dl=0 | — | 2025-08-18 |
| url | https://dl.dropbox.com/scl/fi/4pydbg08752rsw6us7e5x/bobokan.rtf?rlkey=b49lxndnjvigz58o7ptwqrsbm&st=9rtwns0x&dl=0 | — | 2025-08-18 |
| url | https://bp.nidnaver.cloud/info.php | — | 2025-08-18 |
| url | https://bp.nidnaver.cloud/forbhmypresent.66ghz.com/dn.php | — | 2025-08-18 |
| ip | 165.154.52.210 | — | 2025-08-18 |
| ip | 165.154.52.140 | — | 2025-08-18 |
| ip | 158.247.249.243 | — | 2025-08-18 |
| ip | 158.247.230.196 | — | 2025-08-18 |
| ip | 141.164.49.250 | — | 2025-08-18 |
| ip | 141.164.41.17 | — | 2025-08-18 |
| ip | 141.164.40.239 | — | 2025-08-18 |
| md5 | ff37eb655a96b71e7dc08b4d91e1daea | — | 2025-08-18 |
| sha256 | f462439a4590e9ee053573639a82e36304897f0a695729990c108bce6518f556 | — | 2025-08-18 |
| sha256 | f372b16ec015767320a8334b73405943b0222ea125241907235fd4f347832d0e | — | 2025-08-18 |
| md5 | dfacbcf7ef2a3080f9cd785329e7896b | — | 2025-08-18 |
| md5 | da19f3c42361ac84642e936e61c149a1 | — | 2025-08-18 |
| sha256 | cf2cba1859b2df4e927b8d52c630ce7ab6700babf9c7b4030f8243981b1a04fa | — | 2025-08-18 |
| sha256 | c72f52813110685fe16af777f4ea5da2521270b4a906aae2fac98b746e3021ca | — | 2025-08-18 |
| md5 | bca4cac80c436e813d93eba1b25257d0 | — | 2025-08-18 |
| sha256 | 9f5460850a3b5b53568cd450e83406927776833778a8eb24955bcebdf9849321 | — | 2025-08-18 |
| sha256 | 9c5964753f8092a98f414a97cfb02cbe2692a02bea0d1b601ff205282fbf8a62 | — | 2025-08-18 |
| sha256 | 90f53ae46c789884cfddc0d1d8f1ee7f8c4662b899fce51d5b01e94848554072 | — | 2025-08-18 |
| md5 | 8b605de9d28c8c6477a996d4e5873e4e | — | 2025-08-18 |
| md5 | 8a94fe218e7970839b83b53a824ebc47 | — | 2025-08-18 |
| sha256 | 892734d408626a9bb557346c5f80343d5f415e8e536f2aad30df74086865fe50 | — | 2025-08-18 |
| sha256 | 7ac1cb59cf1d5167b4f545c5a49f1c3db71493b448bd81a9a7ad7e25dcd7b943 | — | 2025-08-18 |
| md5 | 752b8fc6f69c8153d6945ff608ae6b4e | — | 2025-08-18 |
| sha256 | 6dea2bf9512f618e3316f58d4f830e2a5cd746b778b125a91403da02de691d89 | — | 2025-08-18 |
| md5 | 60895bbfd40b902513afda50b28e80da | — | 2025-08-18 |
| md5 | 5f704db7552a0b6b535b9c7c5f240664 | — | 2025-08-18 |
| md5 | 5b5d21904d4874da9a31d456c5bcef8f | — | 2025-08-18 |
| sha256 | 4bfd068156adbcaa9c9701abbd72d21c0174f7ce6d3563962891e0538f6a36a7 | — | 2025-08-18 |
📰 Threat Intel Coverage5
Digest reports mentioning this actor (incl. aliases)
| ESET APT Activity Report Q4 2025–Q1 2026 | matched as Kimsuky | 2026-05-28 |
| Threats to the Defense Industrial Base | Google Cloud Blog | matched as APT43 | 2026-02-10 |
| ESET APT Activity Report Q2 2025–Q3 2025 | matched as Kimsuky | 2025-11-06 |
| The Coordinated Embassy Hunt: Unmasking the DPRK-linked GitHub C2 Espionage Campaign | matched as Kimsuky | 2025-08-18 |
| Unmasking ViperSoftX: In-Depth Defense Strategies Against AutoIt-Powered Threats | matched as Kimsuky | 2024-08-29 |