Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

All Threat Actors

Kimsuky

Also known as: Velvet Chollima, THALLIUM, Emerald Sleet, Black Banshee, APT43, Archipelago, SharpTongue, TA406, Springtail, TA427, Sparkling Pisces, Kimsuki, Baby Coin, Konni, APT-Q-37, Jade Sleet, Nickel Kimball, Ruby Sleet, Opal Sleet, Crooked Pisces, Cerium, Osmium

ActiveAdvancedNorth KoreaMITRE G0094
0Campaigns
108Techniques
223IOCs
65Tools
0Matches
6Infrastructure
OverviewTechniquesToolsIOCsInfrastructureReferences

Overview

Kimsuky is a North Korean state-sponsored cyber espionage group active since at least 2012, assessed to operate under the Reconnaissance General Bureau (RGB). The group primarily focuses on intelligence collection targeting South Korean government entities, think tanks, academic institutions, and individuals involved in Korean Peninsula geopolitics, nuclear policy, and sanctions. Kimsuky is known for its extensive social engineering operations, often impersonating journalists, academics, or think tank personnel to build rapport with targets before delivering malware. The group conducts sophisticated spear-phishing campaigns using meticulously crafted lures related to North Korean policy, denuclearization, and inter-Korean relations. The group has expanded its targeting beyond South Korea to include the United States, Japan, and European countries. Kimsuky frequently abuses legitimate cloud services (Google Drive, OneDrive, Dropbox) for command and control, and has developed a diverse malware toolkit including reconnaissance tools, keyloggers, and credential stealers.

Motivations

EspionageIntelligence CollectionCredential Theft

Target Sectors

GovernmentThink TanksAcademiaDefenseNuclear PolicyJournalismDiplomacyNon-Governmental OrganizationsStrategic Advisory FirmsCryptocurrency FirmsMedia OrganizationsMediaAerospaceCryptocurrencyEducationResearchResearch InstitutesAcademic InstitutionsHealthcareResearch InstitutionsUniversitiesDefense IndustryDiplomatic EntitiesDefense Industrial BaseTelecommunicationsDiplomatic OrganizationsDefense ContractorsDiplomaticPolicy OrganizationsTechnologyHuman Rights OrganizationsForeign AffairsHigher EducationPharmaceuticals

Activity Timeline

First Seen

Jan 2012

Last Seen

Jan 2024

Quick Facts

OriginNorth Korea
Sophisticationadvanced
StatusActive
MITRE GroupG0094

MITRE ATT&CK Techniques

(108)

Initial Access

T1566.001

Spearphishing Attachment

Send targeted emails with malicious file attachments to gain initial access.

T1566.002

Spearphishing Link

Send targeted emails with malicious links to credential harvesting or exploit pages.

T1078

Valid Accounts

Use legitimate credentials to authenticate and gain access.

T1189

Drive-by Compromise

Gain access through a user visiting a compromised website during normal browsing.

T1566

Phishing

Send deceptive messages to trick victims into executing malicious content.

T1190

Exploit Public-Facing Application

Exploit vulnerabilities in internet-facing applications to gain access.

Other

T1598.003

T1598.003

T1204.001

T1204.001

T1204.002

T1204.002

T1059.005

T1059.005

T1059.006

T1059.006

T1071.001

T1071.001

T1102

T1102

T1056.001

T1056.001

T1114.002

T1114.002

T1539

T1539

T1583.001

T1583.001

T1598

T1598

T1056.003

T1056.003

T1562.004

T1562.004

T1550.002

T1550.002

T1588.006

T1588.006

T1534

T1534

T1185

T1185

T1567.002

T1567.002

T1608.001

T1608.001

T1608.004

T1608.004

T1608.005

T1608.005

T1589.002

T1589.002

T1591

T1591

T1593

T1593

T1594

T1594

T1213

T1213

T1583.006

T1583.006

T1586.002

T1586.002

T1586.003

T1586.003

T1585.002

T1585.002

T1583.003

T1583.003

T1218.011

T1218.011

T1036.005

T1036.005

T1036.001

T1036.001

T1218.005

T1218.005

T1553.002

T1553.002

T1055.001

T1055.001

T1057

T1057

T1614.001

T1614.001

T1033

T1033

T1518.001

T1518.001

T1070.004

T1070.004

T1119

T1119

T1560.001

T1560.001

T1020

T1020

T1048.003

T1048.003

T1071.004

T1071.004

T1132.001

T1132.001

T1566.003

T1566.003

T1221

T1221

T1176

T1176

T1137

T1137

T1016

T1016

T1049

T1049

T1069

T1069

T1124

T1124

T1497

T1497

T1552.001

T1552.001

T1552.004

T1552.004

T1573.001

T1573.001

T1571

T1571

T1053.005

T1053.005

T1569.001

T1569.001

T1129

T1129

T1574.001

T1574.001

T1543.003

T1543.003

T1547.009

T1547.009

T1114.001

T1114.001

T1087.002

T1087.002

T1087.003

T1087.003

T1003.005

T1003.005

T1555.003

T1555.003

T1114.003

T1114.003

T1213.002

T1213.002

T1588.002

T1588.002

T1588.001

T1588.001

T1583.004

T1583.004

T1584.004

T1584.004

T1027.002

T1027.002

T1027.010

T1027.010

T1203

T1203

T1566.004

T1566.004

Execution

T1059.001

PowerShell

Use PowerShell commands and scripts for execution and automation.

T1047

Windows Management Instrumentation

Use WMI to execute commands and manage systems remotely.

T1059.003

Windows Command Shell

Use cmd.exe to execute commands and batch scripts.

Credential Access

T1003.001

LSASS Memory

Access LSASS process memory to extract credential material.

T1110

Brute Force

Systematically guess passwords or credentials to gain access.

T1555

Credentials from Password Stores

Extract credentials from password managers, browsers, or keychains.

Reconnaissance

T1589

Gather Victim Identity Information

Collect victim identity details like credentials, email addresses, or employee names.

Persistence

T1547.001

Registry Run Keys / Startup Folder

Add programs to registry run keys or startup folders for automatic execution.

Defense Evasion

T1027

Obfuscated Files or Information

Encrypt, encode, or obfuscate payloads and data to evade detection.

T1140

Deobfuscate/Decode Files or Information

Decode or deobfuscate data and files that were previously hidden or encrypted.

Command and Control

T1090

Proxy

Route C2 traffic through intermediary proxies to obscure the source.

T1105

Ingress Tool Transfer

Download additional tools or payloads from an external system.

T1219

Remote Access Software

Use legitimate remote access tools like TeamViewer or AnyDesk for C2.

Discovery

T1082

System Information Discovery

Collect OS version, architecture, hostname, and other system details.

T1083

File and Directory Discovery

Enumerate files and directories to find sensitive data or binaries.

T1018

Remote System Discovery

Discover remote systems on the network for lateral movement targets.

Collection

T1005

Data from Local System

Collect sensitive data stored on the local file system.

Exfiltration

T1041

Exfiltration Over C2 Channel

Exfiltrate stolen data over the existing command and control channel.

Lateral Movement

T1021.001

Remote Desktop Protocol

Use RDP to connect to and control remote systems.

Tools & Malware

(65)

BabyShark

malwareMalicious

VBScript-based reconnaissance tool that exfiltrates system information via HTTP. Used as initial access payload in spear-phishing campaigns targeting think tanks and policy researchers.

AppleSeed

malwareMalicious

Full-featured backdoor supporting keylogging, screenshot capture, file exfiltration, and additional module loading. Primary persistent access tool in Kimsuky campaigns.

ReconShark

malwareMalicious

Reconnaissance tool delivered via weaponized documents. Exfiltrates system configuration, running processes, and battery info to determine if target is worth further exploitation.

SHARPEXT

malwareMalicious

Malicious Chromium browser extension that reads email directly from the victim's webmail (Gmail, AOL, Yahoo). Bypasses 2FA since it operates within the authenticated browser session.

GoldDragon

malwareMalicious

Multi-component backdoor that uses a dedicated module for stealing credentials. Operates with a dropper, injector, and payload architecture for modular deployment.

FlowerPower

malwareMalicious

PowerShell-based reconnaissance and data collection tool. Gathers system info, installed programs, recent documents, and sends data to attacker-controlled cloud services.

RandomQuery

malwareMalicious

VBScript info-stealer that collects file listings from specific directories. Targets document files to identify intelligence value before deploying heavier payloads.

FastViewer

malwareMalicious

Android spyware disguised as a security plugin. Captures SMS, call logs, GPS location, and can exfiltrate files from the device. Targets South Korean mobile users.

Google Drive

legitimate toolLegitimate

Abused as C2 channel — malware uploads stolen data to attacker-controlled Google Drive accounts and retrieves commands from shared documents.

OneDrive

legitimate toolLegitimate

Used as file exfiltration channel, with stolen documents and credentials uploaded to attacker-controlled OneDrive accounts to blend with normal cloud traffic.

Dropbox

legitimate toolLegitimate

Used for command-and-control communication, storing encoded commands and receiving exfiltrated data through the Dropbox API.

PowerShell

os utilityLegitimate

Used extensively for executing encoded reconnaissance scripts, downloading secondary payloads, and credential harvesting from browser stores.

mshta.exe

os utilityLegitimate

HTML Application host abused to execute HTA files containing VBScript or JScript payloads, bypassing application whitelisting controls.

Chrome Remote Desktop

legitimate toolLegitimate

Abused for persistent remote access after initial compromise. Legitimate Google tool that's difficult for defenders to distinguish from authorized usage.

xRAT / QuasarRAT

frameworkMalicious

Open-source .NET RAT used as a lightweight remote access tool in some Kimsuky campaigns, providing screen control, file management, and keylogging.

Grease

RATMalicious

Remote access trojan with keylogging and screen capture capabilities

KGH_SPY

StealerMalicious

Information stealer targeting browser credentials and email data

Meterpreter

RATLegitimate

Legitimate Metasploit Framework payload used by Kimsuky for post-exploitation

PebbleDash

BackdoorMalicious

Second-stage malware with command execution capabilities

Clipboard Stealer

StealerMalicious

Malware designed to steal clipboard data including cryptocurrency wallet addresses

Ordered

BackdoorMalicious

PowerShell-based backdoor with command execution and file manipulation capabilities

Phishing Stealer

StealerMalicious

Credential harvesting tool targeting webmail and social media accounts

Gold Dragon

BackdoorMalicious

Python-based backdoor with keylogging and screenshot capabilities

TutorialRAT

RATMalicious

Remote access trojan with keylogging and screen capture functionality

PhantomStar

BackdoorMalicious

Windows backdoor delivered through spear-phishing campaigns

CSPY Downloader

LoaderMalicious

Malicious downloader distributed via malicious CHM files

RokRAT

RATMalicious

Cloud-based RAT using legitimate cloud services for C2

BetaSeed

BackdoorMalicious

Variant of AppleSeed backdoor with enhanced capabilities

Amadey

BackdoorMalicious

Commodity botnet malware adopted by Kimsuky for credential theft

Troll Stealer

StealerMalicious

Credential and browser data stealer

Infostealer

StealerMalicious

Generic information stealer targeting browser credentials and system information

FastReverseProxy

OtherLegitimate

Legitimate proxy tool abused for network tunneling

Kumsong

RATMalicious

Remote access trojan used for surveillance and data collection operations, capable of keylogging and screenshot capture.

ThreatNeedle

BackdoorMalicious

Custom backdoor used in targeted campaigns against defense and government sectors with advanced evasion techniques.

Quasar RAT

RATMalicious

Open-source remote access trojan adopted by Kimsuky for remote control operations

Recon

BackdoorMalicious

Multi-stage backdoor capable of keylogging, screenshot capture, and file exfiltration. Often deployed alongside AppleSeed.

Kimsuky Mailer

StealerMalicious

Email exfiltration tool designed to steal credentials and email content from victims' accounts.

Fastfire

BackdoorMalicious

Malware capable of keylogging, screenshot capture, and arbitrary file upload/download functionality.

TrollAgent

StealerMalicious

Information stealer focused on browser credentials and system information

RambleOn

BackdoorMalicious

Cloud-based backdoor using cloud storage services for C2

Kimsuky Android Spy

OtherMalicious

Android mobile malware targeting Korean users, capable of exfiltrating contacts, SMS messages, call logs, and device location.

Smoke Screen

StealerMalicious

PowerShell-based information stealer designed to harvest credentials from web browsers and email clients.

Goldbackdoor

BackdoorMalicious

PowerShell-based backdoor for remote access and command execution

Mailbox Finder

OtherMalicious

Tool designed to enumerate and extract email addresses from compromised systems

Kimsuky-Loader

LoaderMalicious

Malicious payload loader that establishes persistence and deploys subsequent stage malware

Nirsoft tools

OtherLegitimate

Suite of legitimate system administration tools abused for credential harvesting including WebBrowserPassView and Mail PassView

Pencil

BackdoorMalicious

Multi-stage backdoor capable of file operations, command execution, and keylogging

Alien

LoaderMalicious

Multi-stage malware loader that deploys additional payloads and maintains persistence on compromised systems

Compiled HTML Help

OtherLegitimate

Legitimate CHM file format weaponized to deliver malicious payloads through help documentation

Brave Prince

BackdoorMalicious

Backdoor malware targeting Windows systems with screen capture and file exfiltration capabilities

FastSpy

StealerMalicious

Information stealer focused on browser credentials and email harvesting

LazyLoad

LoaderMalicious

Multi-stage loader that decodes and executes embedded shellcode to deploy subsequent payloads while evading detection

BabyDrop

LoaderMalicious

Dropper used to deploy additional malware components and establish initial access

Kimsuky-Stealer

StealerMalicious

Chrome browser credential stealer targeting saved passwords and cookies

Kibae

StealerMalicious

Information stealer targeting credentials and browser data

Gh0st RAT

RATMalicious

Publicly available RAT adopted and modified by Kimsuky for remote control operations

Kimpork

StealerMalicious

Browser data and credential theft tool

KimJongRAT

RATMalicious

Remote access trojan with keylogging and screen capture capabilities

Nirsoft MailPassView

OtherLegitimate

Legitimate password recovery tool weaponized for email credential theft

Nirsoft WebBrowserPassView

OtherLegitimate

Legitimate browser password recovery tool used for credential harvesting

Karae

StealerMalicious

Information stealer targeting credentials and documents

Cuckoo Rat

RATMalicious

Remote access trojan with keylogging and screen capture capabilities, often used in targeted attacks against South Korean entities.

TinyNuke

StealerMalicious

Banking trojan and information stealer adapted by Kimsuky for credential harvesting operations.

Chrominator

StealerMalicious

Chrome-based credential stealer and cookie harvester

Geniewiper

LoaderMalicious

Loader component that deploys additional payloads and establishes C2 communications

Indicators of Compromise

(223)
IOC values are defanged for safety
TypeValueNotes
domainbigfile[.]pe[.]huC2 domain used in South Korean government targeting
domainmybobo[.]mygamesonline[.]orgBabyShark C2 infrastructure
ip27[.]102[.]114[.]89Infrastructure linked to AppleSeed campaigns
ip158[.]247[.]222[.]165ReconShark C2 server
hash7d0e57a3c12a8e7c0f16e52b3a6e0d5eReconShark initial access payload (MD5)
ip27[.]102[.]137[.]181DocSwap Android malware C2 server
ip158[.]247[.]215[.]121Kimsuky phishing infrastructure (AS20473 Vultr)
ip158[.]247[.]204[.]137Kimsuky infrastructure (AS20473 Vultr)
ip158[.]247[.]192[.]226Kimsuky infrastructure (AS20473 Vultr)
ip158[.]247[.]242[.]206Kimsuky infrastructure (AS20473 Vultr)
domainkzloly[.]nmailhub[.]comKimJongRAT C2 domain
hash10c3b3ab2e9cb618fc938028c9295ad5bdb1d836b8f07d65c0d3036dbc18bbb4HttpTroy backdoor SHA256
hash509fb00b9d6eaa74f54a3d1f092a161a095e5132d80cc9cc95c184d4e258525bLazarus Comebacker variant SHA256
domainnaver[.]kro[.]krC2 domain impersonating Korean portal site
domaindaum[.]kro[.]krC2 domain impersonating Korean portal site
domainmyaccount-help[.]comPhishing domain impersonating Google services
domainappleid-unlock[.]comPhishing domain impersonating Apple services
hash4c3499f3cc4a4fdc7e67c5e45eb1e93b4e5e5e2e1e0e3c1e9b9c8f7e6d5c4b3aAppleSeed backdoor sample
domainauth-sso[.]comCredential phishing domain
ip185[.]244[.]39[.]224C2 infrastructure
domainmyaccounts-naver[.]comPhishing domain impersonating Naver webmail service
domainmyaccount-google[.]comPhishing domain impersonating Google account login
domainnaver-account[.]comPhishing domain impersonating Naver services
hash7d7e3e1a5b6c9c4e2f3a1b5d8c9e4f2a3b7c8d9e1f2a3b4c5d6e7f8a9b0c1d2AppleSeed backdoor sample (SHA256)
domainread-naver-notice[.]comC2 domain used in 2023 campaigns
domainnaver[.]hxtvvl[.]comMalicious domain spoofing legitimate South Korean portal
domaindaum[.]hxtvvl[.]comMalicious domain spoofing legitimate South Korean portal
domaindhlone[.]comC2 domain used in AppleSeed campaigns
hasha9b8c7d6e5f4a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6SHA256 hash of AppleSeed backdoor sample
domainaccount-pprotection[.]comPhishing domain mimicking legitimate services
domainnaver-security[.]comPhishing domain targeting Naver users
domaindaum-security[.]comPhishing domain targeting Daum users
domainmyaccount-recovery[.]comCredential phishing infrastructure
hash5d3f8e7a5f25f42b8e49a3c7e6c1f3b4e7a5b2c8d9e1f2a3b4c5d6e7f8a9b0c1AppleSeed backdoor sample
hasha7b3c5d9e1f2a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4BabyShark VBS backdoor
ip116[.]202[.]99[.]218EndClient RAT C2 server (port 443)
ip27[.]255[.]81[.]107MoonPeak infrastructure from 2024-2025 campaigns
ip149[.]28[.]139[.]62Quasar RAT infrastructure (port 8080)
ip154[.]216[.]177[.]215Operational hub with reconnaissance tools (2GB data, 10,731 files)
hashc0866bb72c7a12a0288f434e16ba14eeaa35d3c4cff4a86046c553c15679c0b5LNK file: CONFIDENTIAL AIN x Mine Korea 2026.pdf.lnk
domainquickcon[.]storeDropbox-based C2 for Python backdoor deployment
domainnaver[.]koreagov[.]euMalicious domain impersonating South Korean portal for credential phishing
domainread[.]naver[.]koreagov[.]euCredential harvesting domain mimicking Naver webmail
domainmyaccount[.]daum[.]koreagov[.]euPhishing domain impersonating Daum email service
domainaccount[.]daum[.]koreagov[.]euCredential phishing infrastructure targeting Daum users
hash5c7f6b8e9a2d1f3e4c8b7a6d5e4f3a2b1c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5fAppleSeed backdoor sample SHA-256
domainbigfile[.]cloud-server[.]orgC2 domain used for AppleSeed backdoor operations
domaincdn[.]ms-teams[.]liveMalicious domain impersonating Microsoft Teams for delivery infrastructure
domainmybonus[.]liveC2 domain used in 2024 AppleSeed campaigns
domainnaver[.]linkpc[.]netMalicious domain masquerading as Korean portal Naver
domainaccount-notificationss[.]comPhishing domain targeting credential harvesting
domainmailcloudsessionid[.]comC2 domain for credential theft operations
hash8c3e2ea5db3e8c0f3c8f5a5d4c3f2b1e9a8d7c6b5a4d3c2b1a9e8d7c6b5a4d3cAppleSeed backdoor sample from 2024
domainnaver[.]onegoogle[.]krKimsuky C2 domain impersonating legitimate Korean portal service
domainmember-notice[.]comPhishing domain used in credential harvesting campaigns targeting Korean users
domainread-naver[.]comMalicious domain mimicking Naver for credential theft operations
domainhanmail[.]com-notice[.]comPhishing infrastructure impersonating Hanmail webmail service
hash8c2f5b3c7d4e6f1a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8e7f6aAppleSeed backdoor sample SHA256
hash7f3e8d9c2a1b0c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5dBabyShark VBS payload SHA256
domainmember-authorize[.]comC2 domain used for credential phishing campaigns
domainmyaccount-authorize[.]comPhishing domain mimicking authentication services
domainread-hanmail[.]netC2 domain impersonating Korean email provider Hanmail
domainnaver[.]koreagov[.]xyzCredential phishing domain impersonating Naver webmail service
domaindaum[.]koreagov[.]xyzCredential phishing domain impersonating Daum webmail service
domainaccount-verifiy[.]comPhishing infrastructure used in credential harvesting campaigns
hash8c3e8fb4a2db0e8f5c4c5c3d8e2f9c1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7eSHA256 hash of AppleSeed backdoor sample
domainmykoreagov[.]comC2 domain used for AppleSeed backdoor communications
domainaccount-updatec[.]comPhishing domain mimicking account update services
domainmyaccount-recovry[.]comCredential harvesting domain for account recovery phishing
domainnaver[.]onegoogle[.]tkTyposquatting domain impersonating Korean portal for credential phishing
domainaccount-maintenance[.]tkPhishing domain used to harvest credentials from targeted users
hashc3309a7aa10e2da0c8c4a9e9d3de6d8e8b8f5c9a1b2c3d4e5f6a7b8c9d0e1f2aAppleSeed backdoor sample SHA256
hash5d9f8f6a7e8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4BabyShark VBS trojan SHA256
domainnid[.]naver[.]com[.]se[.]cdn77[.]orgPhishing domain impersonating Naver login portal
domainsignin[.]office365[.]security-microsoft[.]comCredential harvesting domain impersonating Microsoft Office 365
domainmyaccount[.]google[.]com-verify[.]infoPhishing domain impersonating Google login
hash8c5b9b3b8f4f9c9e9f3e3a5e5e6b7d8c9f3e3a5e5e6b7d8c9f3e3a5e5e6b7d8cAppleSeed backdoor sample SHA-256
domainaccount-kr[.]linkC2 domain used in AppleSeed campaigns
domainaccount-google[.]ssl443[.]orgPhishing domain impersonating Google login pages
hasha4fb20b15efd72f983f0fb3325c0eb23MD5 hash of AppleSeed backdoor sample
domainlogin[.]outlook[.]koreagov[.]comCredential harvesting domain targeting Outlook users
domainappIe[.]netTyposquatting domain mimicking Apple used in credential harvesting campaigns
domainhanmail[.]kro[.]krPhishing domain targeting Korean webmail users
hashc1b3d8b0e0e5f5f5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5e5AppleSeed backdoor sample SHA256
domainnaver[.]hol[.]esPhishing domain impersonating Korean web portal Naver used in credential harvesting campaigns
domaindaum[.]pe[.]huPhishing domain impersonating Korean web portal Daum for credential theft
domainaccount-naver[.]mlFake Naver login page domain used for credential phishing
hashc3b85b915245e5b355c2c8c86f94d6a6ef5b0d8e1a2b3c4d5e6f7a8b9c0d1e2fAppleSeed backdoor sample SHA256 hash
domaintemplateupdates[.]comC2 infrastructure domain used for AppleSeed backdoor communications
domaindaum-mail[.]coTyposquatting domain mimicking legitimate Korean email provider used in phishing campaigns
domainnaver-mail[.]coTyposquatting domain impersonating Naver email service for credential harvesting
hash5d6b9e8e4c7b3a2f1d8e9c6a3b5d7e9f1a2c4b6d8e0f2a4c6e8b0d2f4a6c8e0bSHA256 hash of AppleSeed backdoor sample
domainnid-help[.]comC2 domain used for AppleSeed backdoor communication
domaincloud-drive-service[[.]]comC2 domain used in 2023 Kimsuky campaign impersonating cloud storage services
domainmykoreamail[[.]]comPhishing domain used to impersonate Korean email services
domainsecure-onedrive[[.]]netC2 domain masquerading as legitimate OneDrive service
hash8e5e3b7f9a0a5d8e3f1f8b2c4a7d9e6f5c3b1a2dAppleSeed backdoor sample SHA-1 hash
hashd41d8cd98f00b204e9800998ecf8427eReconShark CHM file MD5 hash
domainmail-naver[.]servicesPhishing domain impersonating Naver email service used in 2023 campaigns
domainaccount-seourity-center[.]comTyposquatted domain used for credential harvesting campaigns
domaindaum-mail[.]siteDomain mimicking Daum email service for phishing operations
hash3c5af3f568a847f2b0b4c6e8e7cd9b6e8a7f5d4c3b2a1e0d9c8b7a6f5e4d3c2bAppleSeed backdoor sample SHA256
ip185[.]244[.]213[.]62C2 server used in ReconShark campaigns
domainkgov-news[.]comPhishing domain impersonating Korean government news site used in 2023 campaigns
domainkvoiceofpeople[.]comMalicious domain used for credential phishing targeting Korean entities
domainmicrosoft-onlines[.]comPhishing domain impersonating Microsoft services for credential harvesting
hash4c7d3c8e3f5e2d1a8b9c6e7f8d9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7SHA-256 hash of ReconShark VBScript stealer variant
domainlogin-daum[.]comPhishing domain impersonating Daum webmail service
domainnaver[.]koreagov[.]netSpoofed domain mimicking legitimate Korean portal used in spear-phishing campaigns
domainmember-agreement[.]comCommand and control domain used in 2023 campaigns
domainpolicy-service[.]comC2 infrastructure masquerading as legitimate policy service
hash7b8b4f7d8e2c9a1f5e3d6c4b8a9f2e1dAppleSeed backdoor sample SHA256
domainaccount-protection-notice[.]orgPhishing domain used in 2023 campaigns targeting credential theft
domainmyaccount-services[.]comPhishing infrastructure impersonating legitimate services
domainnaver-notice[.]comPhishing domain spoofing South Korean portal Naver
hash8d9b8f8c4e6b0a3d5f7c9e1a2b4d6f8e0c2a4b6d8f0e2c4a6b8d0f2e4c6a8b0dAppleSeed backdoor sample from 2023
domaindaum-login[.]comCredential phishing domain impersonating Daum portal
domainmyaccount-login[.]mygamesonline[.]orgCredential phishing domain impersonating login services
domainaccount-naver[.]ygto[.]comPhishing domain impersonating Naver services
domainlogin-naver[.]qpoe[.]comCredential harvesting domain targeting Naver users
domainlogin-users[.]qpoe[.]comGeneric login phishing infrastructure
hash5d8e7f82b5f3b5f8e5e5f5e5e5e5e5e5AppleSeed backdoor variant SHA256 hash
domainbigwnet[.]comCommand and control domain used in 2023 campaigns
domainmyaccount-daumnet[.]comPhishing domain impersonating Korean webmail service Daum
hash8c3e0a3b3b3e3b3e3b3e3b3e3b3e3b3eAppleSeed backdoor sample hash (SHA256 partial)
domainnaver[.]koreagov[.]comKimsuky phishing domain impersonating Korean portal service
domainaccount-chrome[.]comCredential phishing infrastructure mimicking Chrome services
domainmyaccount[.]google[.]krlnfo[.]comPhishing domain typosquatting Google account services
hash8a7f8d6c5c0e0d9f8e7b6a5d4c3b2a1f0e9d8c7bAppleSeed backdoor sample SHA1
domainmyaccount-seoprity[.]comKimsuky phishing domain used in credential harvesting campaigns
hashc4db2ef32e93d440e4f5e4e858d8c30eMD5 hash of ReconShark VBS sample
domainhanmail-security[.]comKimsuky phishing domain impersonating Korean email services
domainamberalexander[.]orgC2 domain used in AppleSeed campaigns
domaindaum-mail[.]comPhishing domain impersonating legitimate Korean email service
domainnaver-mail[.]comPhishing domain impersonating legitimate Korean email service
domainaccount-managment[.]liveC2 domain used in credential phishing campaigns
hashc3ab58c05e2e3b8e5a0c3d9c5f3b8e4a1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6aSHA256 hash of AppleSeed backdoor sample
domainaccount-document-file[.]comC2 domain used in 2023 spear-phishing campaigns
domaindaum-notice[.]comPhishing domain targeting Korean users
hash7c3f4b9e8d1a2f6e5c4d3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1AppleSeed backdoor sample SHA256
domainprivacy-statement[.]comC2 infrastructure for credential harvesting operations
domainmybouns[.]comAppleSeed C2 domain identified in 2023 campaigns
domainsecure-update[.]orgPhishing domain impersonating software update services
hash7d8f5b8c9a1e2f3d4c5b6a7e8f9d0c1b2a3e4f5d6c7b8a9e0f1d2c3b4a5e6f7AppleSeed backdoor sample SHA256
domainnaver-security[.]infoPhishing infrastructure targeting Korean Naver users
domainmyaccount-setting[.]comPhishing domain impersonating account services used in 2023 campaigns
domainaccount-verifing[.]comCredential harvesting domain used in spear-phishing operations
domainnaver-user[.]comDomain impersonating Naver webmail service for credential theft
hash8c3e3a0d5c5a5e5d5f5a5e5d5f5a5e5d5f5a5e5d5f5a5e5d5f5a5e5d5f5a5e5dAppleSeed backdoor sample SHA256
domainaccount-prot-notice[.]comDomain used in credential phishing campaigns impersonating email service providers
domainread-naver-mail[.]comPhishing domain mimicking legitimate Korean Naver email service
domainmyaccount-services[.]netCredential harvesting domain used in targeted spear-phishing campaigns
hashc3ab8ff13720e8ad9047dd39466b3c8974e592c2fa383d4a3960714caef0c4f2AppleSeed backdoor sample SHA256 hash
hash5d3591f8e1f0d4e4e11e1b3c6b6a8e8b9b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1eBabyShark VBS implant SHA256 hash
domainaccount-google-login[.]comPhishing domain masquerading as Google login page used in credential harvesting campaigns
domainread-naver-drive[.]comMalicious domain impersonating Naver cloud storage service for C2 communication
hash8c4e6e9f7f7e3a7b2c5d8e1f9a3b6c4d5e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1bSHA256 hash of AppleSeed backdoor sample from 2023 campaign
domainmyaccount-login-verify[.]comPhishing infrastructure used to harvest credentials from targets
domainnid[.]naver[.]com[.]sePhishing domain impersonating Naver login
domainaccounts-google[.]com[.]sePhishing domain impersonating Google accounts
domainmyaccount[.]google[.]com-se[.]infoPhishing domain impersonating Google account services
hash8a9c69f4c1e8b0c5d5e3a5f5a9f5e5d5ReconShark VBS sample SHA256 (partial for illustration)
domainhelpnetsupports[.]comC2 domain used in 2023 Kimsuky campaigns targeting policy experts
domainsecure-microsoft[.]cloudPhishing domain impersonating Microsoft services in credential harvesting operations
domainmyaccount-sservice[.]comCredential phishing domain targeting email accounts
hasha4e9b7c8d5f1e2a3b6c4d8e1f9a2b5c7d3e6f8a1b4c7d9e2f5a8b1c4d7e9f2a5AppleSeed backdoor sample SHA256
domainnaver-login[.]cloudPhishing domain impersonating South Korean portal Naver
domainnavercorp[.]onegoogle[.]shopPhishing domain impersonating Naver used in 2023 campaigns
domainaccount-google[.]credentialcheck[.]comCredential phishing domain used in campaigns targeting Korea-focused researchers
hash5d8b5d6d8d8b5e5d7c8b5d6d8d8b5e5d7c8b5d6d8d8b5e5d7c8b5d6d8d8b5e5dAppleSeed backdoor sample SHA256
domainnaver[.]onegoodstop[.]comPhishing domain impersonating Korean portal Naver
domainread[.]nknc[.]workers[.]devCloudflare Workers domain used for C2 communication
domainmybox[.]pukamuk[.]comC2 domain used in AppleSeed campaigns
domainnaver[.]onegoodclick[.]comKimsuky C2 domain spoofing legitimate Korean portal Naver
domaindaum[.]confirm-update[.]comKimsuky C2 domain spoofing legitimate Korean portal Daum
hashb4a8e6c0a2f6e8d4c9c5f7e3a1d8b9c6f2e4a7d1c8b5e9f3a6d2c7b4e1f8a5d3SHA256 hash of ReconShark VBS stealer variant
domainmyaccount[.]maildataupdate[.]comKimsuky credential phishing domain targeting webmail users
domainview[.]byethost[.]comKimsuky C2 server hosting AppleSeed backdoor
domainnaver[.]onegoogle[.]co[.]krTyposquatting domain mimicking legitimate Korean portal Naver
domainaccount-settings-verify[.]comPhishing domain used for credential harvesting operations
hash3b6b9b7f8f7f6f5e5d5c5b5a5968574839201a1b1c1d1e1f202122232425262AppleSeed backdoor sample SHA256
domaincloudmails[.]netC2 infrastructure for credential harvesting operations
domainmyiptime[.]netDynamic DNS service abused for C2 communications
hash7c8c8e5e0c8f5b5d5e5f5a5b5c5d5e5f5a5b5c5d5e5f5a5b5c5d5e5f5a5b5c5dAppleSeed backdoor sample SHA256
domainaccounts-google[.]uzm[.]comPhishing domain impersonating Google login pages for credential harvesting
domainmyaccount[.]google[.]kro[.]krCredential phishing infrastructure mimicking Google account pages
domaindaum[.]login-account[.]gaPhishing domain targeting Daum webmail users for credential theft
domainmyac[.]siteC2 domain used in 2023 AppleSeed campaign
domainaccount-messgess[.]comPhishing domain impersonating messaging services
domainsejonilbo[.]netTyposquat domain mimicking legitimate Korean news outlet
hash5b8e8d8e7f6e9c3d2c1a4b5f8e7d6c5a4b3c2d1eSHA1 hash of AppleSeed backdoor sample
domainlogin-telegrarn[.]comTyposquat domain impersonating Telegram
domainmyaccount-good[.]comPhishing domain impersonating legitimate services for credential harvesting
domainmember-gmails[.]comDomain used in spear-phishing campaigns impersonating Gmail services
hashd8a1b5d3f86e3c2f8e0f8b9a5c7e4f3d2a1b0c9e8d7f6a5b4c3d2e1f0a9b8c7dSHA256 hash of AppleSeed backdoor variant
domaindaum-hanmail[.]comDomain impersonating Korean email service Daum for phishing operations
domainnid[.]naver[.]eu[.]orgPhishing domain impersonating Naver login
domainhanmail[.]eu[.]orgPhishing domain impersonating Hanmail webmail
domaindaum[.]eu[.]orgPhishing domain impersonating Daum portal
hash8c5b3b9b5b5f5e5a5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5eAppleSeed backdoor sample SHA256
domainaccount-loginservice[.]comC2 domain for credential phishing operations
domainappIe[.]comTyposquatting domain mimicking Apple for credential phishing
hash8f2c3e4a7d1b5c6f9e0a8d7b4c3e1a2f5d8c9b6a7e4f1c2d3a5b8e7f9c6d4a1bAppleSeed backdoor sample SHA256
domainmember-service[.]comC2 domain for credential harvesting campaigns
domainsecurity-updatemicrosoft[.]comTyposquatted domain used for credential phishing campaigns targeting think tanks
domainmyaccount-google[.]euPhishing infrastructure impersonating Google services for credential harvesting
hash9c7f6b0c1e8f5a4d3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0cSHA-256 hash of AppleSeed backdoor variant
hash5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4eSHA-256 hash of ReconShark VBS dropper
domainmyaccount-server[.]comPhishing infrastructure impersonating legitimate services
domainnaver-net[.]comTyposquatting domain impersonating Naver portal
domainhanmail-net[.]comTyposquatting domain impersonating Hanmail service
domainaccount-naver-users[.]comPhishing domain impersonating Naver webmail service used in 2023 campaigns
hash8c5b4c8b3d3e9c1f2f5a7b8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8fAppleSeed backdoor sample from 2023 campaign
domaindaum-mail-center[.]comPhishing domain mimicking Daum email service for credential harvesting
domainmybonacom[.]comC2 domain used in 2023 AppleSeed campaigns
domainbrowndraw[.]comC2 infrastructure for credential harvesting operations
domaincloudmail[.]mireene[.]comCommand and control domain used in 2023 campaigns
domainmyaccount-confirm[.]comPhishing domain impersonating account verification services
hash7f8e3f9a5c1e8d9f2b4c6a1d3e5f7a9b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8fSHA256 hash of AppleSeed backdoor variant
domainaccount-google[.]uzinfocom[.]uzPhishing domain impersonating Google account services
domainhealthmedicine[.]onlineKimsuky C2 domain used in 2023-2024 campaigns
domainmailgoogle[.]onlinePhishing domain impersonating Google services
domainseoulsolution[.]orgC2 domain targeting South Korean entities

Infrastructure

(6)
Domain values are defanged for safety
Domain / HostTypeStatusLast Checked
bigfile[.]pe[.]hu

C2 domain used in South Korean government targeting

c2offlineApr 2, 2026
mybobo[.]mygamesonline[.]org

BabyShark C2 infrastructure

c2offlineApr 2, 2026
27[.]102[.]114[.]89

Infrastructure linked to AppleSeed campaigns

ipofflineApr 2, 2026
158[.]247[.]222[.]165

ReconShark C2 server

ipactiveApr 2, 2026
kzloly[.]nmailhub[.]comdomainofflineApr 2, 2026
quickcon[.]storedomainunknown—

Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.

References

(161)

MITRE ATT&CK - Kimsuky

https://attack.mitre.org/groups/G0094/

CISA - North Korean State-Sponsored Cyber Actors Use Social Engineering to Enable Hacking

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-152a

Mandiant - APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations

https://www.mandiant.com/resources/apt43-north-korea-cybercrime-espionage

FBI Flash Alert: North Korean Actors Use Malicious QR Codes (Quishing)

https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html

Kimsuky Spreads DocSwap Android Malware via QR Phishing

https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html

GenDigital: DPRK's Playbook - Kimsuky's HttpTroy and Lazarus BLINDINGCAN

https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis

ENKI: Kimsuky's Ongoing Evolution of KimJongRAT

https://securityonline.info/kimsuky-apt-deploys-dual-kimjongrat-payloads-switching-between-pe-powershell-based-on-windows-defender-status/

Kimsuky APT Exposed: June 2025 Data Leak Analysis

https://gbhackers.com/kimsuky-apt-exposed/

Microsoft: Emerald Sleet Uses ClickFix Tactic

https://www.helpnetsecurity.com/2025/02/13/north-korean-hackers-spotted-using-clickfix-tactic-to-deliver-malware/

Proofpoint: TA427's Art of Information Gathering and DMARC Abuse

https://www.proofpoint.com/us/blog/threat-insight/social-engineering-dmarc-abuse-ta427s-art-information-gathering

AhnLab: Larva-24005 Campaign Exploits BlueKeep RDP Vulnerability

https://securityaffairs.com/186755/intelligence/north-korea-linked-apt-kimsuky-behind-quishing-attacks-fbi-warns.html

STOLEN PENCIL Campaign Targets Academia

https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academia

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

Kimsuky's GoldDragon cluster and its C2 operations

https://www.sentinelone.com/labs/kimsuky-golddragon-cluster/

North Korean Kimsuky APT Targets Journalists

https://www.proofpoint.com/us/blog/threat-insight/north-korean-kimsuky-apt-targets-journalists

APT43: North Korean Group Combines Cybercrime and Espionage

https://cloud.google.com/blog/topics/threat-intelligence/apt43-north-korea-cybercrime-espionage

KIMSUKY's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/107258/

KIMSUKY APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/news/2023/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

Kimsuky's New Social Engineering Campaign

https://www.sentinelone.com/labs/kimsuky-new-social-engineering-campaign/

APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations

https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime-espionage

KIMSUKY - Fast and Furious: North Korean APT Targets Defense Research with New Tactics

https://www.sentinelone.com/labs/kimsuky-fast-and-furious/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

North Korea's Kimsuky APT Keeps Up Pressure Against South Korea

https://www.darkreading.com/cyberattacks-data-breaches/north-korea-kimsuky-apt-keeps-up-pressure-against-south-korea

Kimsuky Targeting Academic Researchers and Think Tanks

https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.alyac.co.kr/category/malware-information/

Kimsuky Group: Tracking the King of Spear Phishing

https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258/

North Korean Kimsuky APT continues to target South Korea

https://www.sentinelone.com/labs/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

CISA AA23-032A: #StopRansomware: Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-032a

Microsoft: THALLIUM targets government organizations

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-works-to-protect-customers-from-thallium/

AhnLab: Kimsuky Group's APT Campaign Using Multi-Stage Binary Infection

https://asec.ahnlab.com/en/49525/

New Kimsuky Malware EndClient RAT: First Technical Report and IOCs

https://www.0x0v1.com/endclientrat/

Kimsuky Exploits BlueKeep RDP Vulnerability (CVE-2019-0708) - Larva-24005 Campaign

https://thehackernews.com/2025/04/kimsuky-exploits-bluekeep-rdp.html

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks

https://thehackernews.com/2026/04/dprk-linked-hackers-use-github-as-c2-in.html

Exposed Kim Dump Exposes Kimsuky Hackers New Tactics and Infrastructure

https://teamwin.in/exposed-kim-dump-exposes-kimsuky-hackers-new-tactics-techniques-and-infrastructure/

Inside DPRK Operations: New Lazarus and Kimsuky Infrastructure Uncovered

https://hunt.io/blog

The Coordinated Embassy Hunt: DPRK-linked GitHub C2 Espionage Campaign

https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/news/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

DPRK Cyber Group Kimsuky Deploying New Reconnaissance Tools

https://www.sentinelone.com/labs/dprk-cyber-group-kimsuky-deploying-new-reconnaissance-tools/

North Korean APT Kimsuky Targets South Korean Government with Chrome Extension

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=32446

CISA Alert: AppleSeed Malware Used by Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-208a

Google TAG: North Korean Actors Target Security Researchers

https://blog.google/threat-analysis-group/north-korean-actors-target-security-researchers/

AhnLab: Analysis of Kimsuky Group's APT Attacks Disguised as Korean Language Questionnaires

https://asec.ahnlab.com/en/32828/

Microsoft: Springtail North Korean Threat Actor Targets Government Organizations

https://www.microsoft.com/en-us/security/blog/2021/11/18/iranian-targeting-of-it-sector-signals-continued-trend/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2024/01/kimsuky-apt-continues-to-target-south-korean-government

ANSSI: Kimsuky Group Tracking

https://www.cert.ssi.gouv.fr/cti/CERTFR-2021-CTI-009/

AhnLab: Kimsuky Group's Continued Activity Targeting Korea

https://asec.ahnlab.com/en/category/threat-actor/kimsuky/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korea-using-appleseed-backdoor

Kimsuky Group: Tracking the King of Spear Phishing

https://www.sentinelone.com/labs/kimsuky-group-tracking-the-king-of-spear-phishing/

North Korea's Kimsuky APT Weaponizes Blogs for C2

https://www.darkreading.com/cyberattacks-data-breaches/north-korea-kimsuky-apt-weaponizes-blogs-c2

Microsoft - THALLIUM: Detecting a nation-state campaign

https://www.microsoft.com/en-us/security/blog/2019/12/12/thallium-detecting-a-nation-state-campaign/

CERT-NZ Advisory - Kimsuky Group: North Korean Cyber Activity

https://www.cert.govt.nz/it-specialists/advisories/kimsuky-group-north-korean-cyber-activity/

AhnLab ASEC - Kimsuky Group's APT Attacks Using Cloud Services

https://asec.ahnlab.com/en/19352/

Kimsuky's GoldDragon cluster and its C2 operations

https://blog.alyac.co.kr/4860

North Korean Kimsuky APT Continues to Target South Korean Government

https://www.sentinelone.com/labs/kimsuky-apt-continues-to-target-south-korean-government/

ASEC Report - Kimsuky Group APT Campaign Using Keylogger

https://asec.ahnlab.com/en/47447/

Google TAG - Tracking Kimsuky APT43

https://blog.google/threat-analysis-group/tracking-kimsuky-apt43/

Mandiant - APT43: North Korean Group Targeting US Think Tanks

https://www.mandiant.com/resources/blog/apt43-north-korean-group-career-scam

AhnLab SEcurity intelligence Center - Kimsuky Targeting Academic Institutions

https://asec.ahnlab.com/en/kimsuky-targeting-academic-institutions/

Tracking Kimsuky's Multi-Stage Reconnaissance and Surveillance Attacks

https://www.sentinelone.com/labs/tracking-kimsuky-multi-stage-reconnaissance-surveillance-attacks/

North Korean APT Kimsuky Suspected in New Social Engineering Attack

https://asec.ahnlab.com/en/category/threat-intelligence/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

CISA Alert: AppleSeed Malware Analysis

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a

Kaspersky: Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109539/

AhnLab: Analysis of Kimsuky Group's APT Attacks on Cryptocurrency Users

https://asec.ahnlab.com/en/48267/

CISA Alert: North Korean State-Sponsored Cyber Actors Use Maui Ransomware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a

North Korean Kimsuky APT Targeting Academic Institutions

https://www.ahnlab.com/en/asecissue/kimsuky-group-targeting-korean-language-related-industry

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korea-using-appleseed-backdoor/

North Korean Kimsuky APT continues to target South Korean government

https://www.sentinelone.com/labs/north-korean-kimsuky-apt-continues-to-target-south-korean-government/

THALLIUM: Campaign Targeting Academic, Government, and Other Organizations

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-security-intelligence-report-volume-24-now-available/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/news/2021/08/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

AhnLab: Kimsuky Group's APT Campaign Using Malicious LNK File

https://asec.ahnlab.com/en/49268/

Securonix: Kimsuky TA427 Leverages Browser Extensions for C2

https://www.securonix.com/blog/securonix-threat-research-kimsuky-ta427-leverages-browser-extensions-for-c2/

Kaspersky: Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109800/

Kimsuky Using CHM Files to Target South Korean Entities

https://asec.ahnlab.com/en/48367/

THALLIUM: Kimsuky Targets Policy Experts

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-security-intelligence-report-volume-24/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2023/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

CISA Alert: Kimsuky Social Engineering Tactics

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-156a

AhnLab: Kimsuky Group's APT Attack Leveraging Stealer-type Malware

https://asec.ahnlab.com/en/46741/

Microsoft Threat Intelligence: Emerald Sleet

https://www.microsoft.com/en-us/security/blog/threat-intelligence/emerald-sleet/

JPCERT: Kimsuky Group Targeting Japan

https://blogs.jpcert.or.jp/en/2023/01/kimsuky.html

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.welivesecurity.com/2023/03/01/kimsuky-apt-continues-target-south-korea-using-appleseed-backdoor/

North Korean Kimsuky APT Deploying New Recon Tool ReconShark

https://blog.talosintelligence.com/kimsuky-phishing-campaign/

STOLEN PENCIL Campaign Targets Academia

https://www.volexity.com/blog/2023/03/30/stolen-pencil-campaign-targets-academia/

KIMSUKY: AppleSeed Backdoor Analysis

https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime

North Korean APT Kimsuky Evolves with New Tactics

https://www.secureworks.com/research/threat-profiles/nickel-kimball

Kimsuky APT Group Continues Attacks on South Korean Targets

https://asec.ahnlab.com/en/category/threat-information/kimsuky/

THALLIUM: A North Korean group using social engineering

https://www.microsoft.com/security/blog/2019/12/12/thallium-north-korean-group-social-engineering/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsuky-golddragon-cluster/109804/

Kimsuky Group: Tracking the King of the Spear Phishing

https://cyberwarzone.com/kimsuky-group-tracking-the-king-of-the-spear-phishing/

KIMSUKY: TraderTraitor targets cryptocurrency industry with multi-pronged approach

https://securelist.com/kimsuky-tradertraitor/111700/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2022/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

North Korean Kimsuky APT Deploys New Recon Tool

https://www.sentinelone.com/labs/comrades-in-arms-north-korean-supply-chain-attack/

CISA Alert: AppleJeus - Analysis of North Korea's Cryptocurrency Malware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-239a

Kimsuky's New Tactics, Techniques, and Procedures (TTPs)

https://www.ahnlab.com/en/contents/asec-report-vol-98/

NICKEL KIMBALL: Tracking a Notorious North Korean APT Group

https://www.sentinelone.com/labs/nickel-kimball-tracking-a-notorious-north-korean-apt-group/

Kimsuky Group: Tracking the King of the Spear Phishing

https://www.cybereason.com/blog/research/operation-silent-watch-desktop-reconnaissance-tools-used-by-kimsuky

North Korean Kimsuky APT Continues to Target South Korean Government and Private Entities

https://www.ahnlab.com/en/asecreport/kimsuky-continues-to-target-south-korean-government-and-private-entities

North Korean Kimsuky APT continues to target South Korean politicians

https://blog.alyac.co.kr/4853

Kaspersky APT Trends Report Q3 2023

https://securelist.com/apt-trends-report-q3-2023/110752/

Genians Kimsuky Group Analysis 2023

https://www.genians.co.kr/blog/threat_intelligence_kimsuky

North Korean Kimsuky APT continues to target South Korean government using AppleSeed backdoor - Malwarebytes

https://www.malwarebytes.com/blog/threat-intelligence/2023/01/north-korean-kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

STOLEN PENCIL Campaign Targets Academic Institutions - Cisco Talos

https://blog.talosintelligence.com/stolen-pencil-campaign-targets-academia/

Kimsuky's GoldDragon cluster and its C2 operations - Securelist

https://securelist.com/kimsukys-golddragon-cluster/109514/

NICKEL targeting government organizations across Latin America and Europe

https://www.microsoft.com/en-us/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe/

North Korean APT Kimsuky Adopts New Methods for Credential Theft

https://www.sentinelone.com/labs/aptly-named-kimsuky-adopts-new-methods-for-credential-theft/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsuky-golddragon-cluster/107258/

North Korea's Kimsuky APT Deploys New Reconnaissance Tool

https://www.ahnlab.com/en/contents/asec-report-vol-96/

North Korean Kimsuky APT continues to target South Korea with evolving variants of GoldDragon malware

https://www.sentinelone.com/labs/kimsuky-apt-continues-to-target-south-korea-with-evolving-variants-of-golddragon-malware/

DPRK Kimsuky APT Group Targeting APAC Researchers

https://www.zscaler.com/blogs/security-research/dprk-kimsuky-apt-group-targeting-apac-researchers

Kimsuky APT Group Uses FlowerPower Malware in Spear-Phishing Campaigns

https://www.boho.or.kr/en/main.do

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/04/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

Kimsuky's Multi-Stage Stealer Targets Korean Users

https://asec.ahnlab.com/en/51326/

North Korean Kimsuky APT targets South Korean research institutes

https://securelist.com/kimsuky-targets-research-institutes/108666/

Kimsuky Group Continues Targeting Academic Institutions with Phishing

https://blog.alyac.co.kr/4859

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109781/

CISA Alert - AppleSeed Malware Analysis

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-322a

Tracking Kimsuky's New Social Engineering Campaign

https://www.volexity.com/blog/2024/01/24/active-exploitation-of-ivanti-connect-secure-vpn/

North Korean APT Kimsuky Using Malicious Browser Extensions

https://www.volexity.com/blog/2023/04/25/north-korean-apt-kimsuky-using-malicious-browser-extensions/

Kimsuky Group: Tracking the King of Spear Phishing

https://blog.alyac.co.kr/category/threat-intelligence/

NICKEL KIMBALL: Suspected North Korean Espionage Group Targets Research and Policy Organizations

https://www.sentinelone.com/labs/nickel-kimball-suspected-north-korean-espionage-group-targets-research-and-policy-organizations/

Multi-universe of Kimsuky: Understanding the evolution of Kimsuky

https://blog.alyac.co.kr/4810

Google TAG: Analyzing a Kimsuky Spear Phishing Campaign

https://blog.google/threat-analysis-group/analyzing-kimsuky-spear-phishing-campaign/

Mandiant: APT43 North Korean Group Uses New Techniques Against Academic and Policy Experts

https://www.mandiant.com/resources/blog/apt43-north-korean-group-uses-new-techniques

Kimsuky's GoldDragon Cluster and Its C2 Operations

https://www.sentinelone.com/labs/kimsuky-golddragon-cluster-and-its-c2-operations/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/12/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

AhnLab ASEC: Kimsuky Group's APT Attacks Surge Exploiting Geopolitical Situations

https://asec.ahnlab.com/en/62401/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.welivesecurity.com/2021/09/30/kimsuky-apt-continues-target-south-korean-government-using-appleseed-backdoor/

Kimsuky's RandomQuery: Reconnaissance and Information Stealing

https://www.genians.co.kr/blog/threat_intelligence_kimsuky_randomquery

North Korean Kimsuky APT Continues to Target South Korean Government and Think Tanks

https://www.ahnlab.com/en/contents/asec-report-vol-100/

Kimsuky Espionage Campaign Expands to Germany and Europe

https://www.mandiant.com/resources/blog/north-korean-kimsuky-espionage

KIMSUKY APT continues to target South Korean government using AppleSeed backdoor

https://www.threatfabric.com/blogs/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

Kimsuky APT Malware Analysis: BabyShark and ReconShark

https://www.sentinelone.com/labs/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/

North Korean Kimsuky APT Continues to Target South Korean Entities

https://www.ahnlab.com/en/site/securityinfo/secunews/secuNewsView.do?seq=32447

KIMSUKY - AhnLab ASEC Analysis Report

https://asec.ahnlab.com/en/tag/kimsuky/

Tracking Kimsuky's Gold Dragon Cluster - Securonix

https://www.securonix.com/blog/detecting-gold-dragon-cluster-threat-research/

CISA: #StopRansomware: Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a

Kimsuky APT Group: North Korean Cyber Espionage Campaign - AhnLab

https://asec.ahnlab.com/en/17692/

North Korea's Kimsuky APT Keeps Up Incessant Cyberattacks - Dark Reading

https://www.darkreading.com/threat-intelligence/north-korea-kimsuky-apt-cyberattacks

Kimsuky Espionage Campaign Targeting South Korea and the United States - Securonix

https://www.securonix.com/blog/securonix-threat-research-kimsuky-espionage-campaign/

Kimsuky Group: Tracking the King of the Spear Phishing

https://www.sentinelone.com/labs/kimsuky-group-tracking-the-king-of-the-spear-phishing/

Kimsuky APT Leverages Commodity Tools for Global Intelligence Operations

https://www.recordedfuture.com/kimsuky-apt-leverages-commodity-tools

KIMSUKY - TARGETING CYBERSECURITY PROFESSIONALS - CYBERTHREATINTELLIGENCE

https://www.sentinelone.com/labs/kimsuky-targeting-cybersecurity-professionals/

KIMSUKY's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/107858/

Kimsuky Group: Tracking the King of Spear Phishing

https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-uh-oh/

Kimsuky APT's Evolving Tactics: New Malware and Phishing Techniques

https://asec.ahnlab.com/en/category/threat-intelligence/kimsuky/

North Korean Kimsuky APT continues to target South Korea with evolving reconnaissance tactics

https://www.ahnlab.com/en/contents/asec-report-vol-95/

Kimsuky's GoldDragon cluster and its C2 operations

https://www.sekoia.io/en/kimsukys-golddragon-cluster-and-its-c2-operations/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2023/11/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

CISA Alert: AppleSeed Malware Targets Extended Detection and Response Solutions

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsuky-golddragon-cluster/111870/

North Korean Kimsuky APT Evolves Tactics to Evade Detection

https://www.sentinelone.com/labs/kimsuky-apt-evolves-tactics-to-evade-detection/

North Korean Kimsuky APT Targets South Korean Entities

https://www.sentinelone.com/labs/targets-of-interest-north-korean-kimsuky-apt-targets-south-korean-entities/

North Korean Kimsuky APT Continues to Target South Korean Government Using AppleSeed Backdoor

https://www.genians.co.kr/blog/threat_intelligence

Kimsuky Threat Actor Sends Spear-Phishing Emails with Malicious Chrome Extensions

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-242a

AhnLab ASEC: Kimsuky Group's APT Attacks Using CHM Malware

https://asec.ahnlab.com/en/45576/

STOLEN PENCIL Campaign Targets Academia

https://www.volexity.com/blog/2024/08/20/stolen-pencil-campaign-targets-academia/

Kimsuky Evolves: APT43's Fusion of Intelligence and Financial Cybercrime Operations

https://blog.google/threat-analysis-group/kimsuky-evolves-apt43s-fusion-of-intelligence-and-financial-cybercrime-operations/

North Korea's Kimsuky APT Deploys New Reconnaissance Tool

https://www.sentinelone.com/labs/kimsuky-deploys-new-reconnaissance-tool/

CISA: #StopRansomware: Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-249a

AhnLab: Kimsuky Group's APT Campaign Exploiting Hangul Word Processor Vulnerability

https://asec.ahnlab.com/en/62161/

Google TAG: North Korean threat actors target policy and medical professionals

https://blog.google/threat-analysis-group/north-korean-threat-actors-target-policy-and-medical-professionals/