Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
Log → SplunkLog → Sentinel
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckLog → SplunkLog → SentinelAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

All Threat Actors

Kimsuky

Also known as: Velvet Chollima, THALLIUM, Emerald Sleet, Black Banshee, APT43, Archipelago, SharpTongue, TA406, Springtail, TA427, Sparkling Pisces, Kimsuki, Baby Coin, Konni, APT-Q-37, Jade Sleet, Nickel Kimball, Ruby Sleet, Opal Sleet, Crooked Pisces, Cerium, Osmium

ActiveAdvancedNorth KoreaMITRE G0094
0Campaigns
108Techniques
319IOCs
88Tools
0Matches
6Infrastructure
OverviewTechniquesToolsIOCsInfrastructureReferences

Overview

Kimsuky is a North Korean state-sponsored cyber espionage group active since at least 2012, assessed to operate under the Reconnaissance General Bureau (RGB). The group primarily focuses on intelligence collection targeting South Korean government entities, think tanks, academic institutions, and individuals involved in Korean Peninsula geopolitics, nuclear policy, and sanctions. Kimsuky is known for its extensive social engineering operations, often impersonating journalists, academics, or think tank personnel to build rapport with targets before delivering malware. The group conducts sophisticated spear-phishing campaigns using meticulously crafted lures related to North Korean policy, denuclearization, and inter-Korean relations. The group has expanded its targeting beyond South Korea to include the United States, Japan, and European countries. Kimsuky frequently abuses legitimate cloud services (Google Drive, OneDrive, Dropbox) for command and control, and has developed a diverse malware toolkit including reconnaissance tools, keyloggers, and credential stealers.

Motivations

EspionageIntelligence CollectionCredential Theft

Target Sectors

GovernmentThink TanksAcademiaDefenseNuclear PolicyJournalismDiplomacyNon-Governmental OrganizationsStrategic Advisory FirmsCryptocurrency FirmsMedia OrganizationsMediaAerospaceCryptocurrencyEducationResearchResearch InstitutesAcademic InstitutionsHealthcareResearch InstitutionsUniversitiesDefense IndustryDiplomatic EntitiesDefense Industrial BaseTelecommunicationsDiplomatic OrganizationsDefense ContractorsDiplomaticPolicy OrganizationsTechnologyHuman Rights OrganizationsForeign AffairsHigher EducationPharmaceuticalsNuclear Policy ResearchCryptocurrency IndustryEnergy

Activity Timeline

First Seen

Jan 2012

Last Seen

Jan 2024

Quick Facts

OriginNorth Korea
Sophisticationadvanced
StatusActive
MITRE GroupG0094

MITRE ATT&CK Techniques

(108)

Initial Access

T1566.001

Spearphishing Attachment

Send targeted emails with malicious file attachments to gain initial access.

T1566.002

Spearphishing Link

Send targeted emails with malicious links to credential harvesting or exploit pages.

T1078

Valid Accounts

Use legitimate credentials to authenticate and gain access.

T1189

Drive-by Compromise

Gain access through a user visiting a compromised website during normal browsing.

T1566

Phishing

Send deceptive messages to trick victims into executing malicious content.

T1190

Exploit Public-Facing Application

Exploit vulnerabilities in internet-facing applications to gain access.

Other

T1598.003

T1598.003

T1204.001

T1204.001

T1204.002

T1204.002

T1059.005

T1059.005

T1059.006

T1059.006

T1071.001

T1071.001

T1102

T1102

T1056.001

T1056.001

T1114.002

T1114.002

T1539

T1539

T1583.001

T1583.001

T1598

T1598

T1056.003

T1056.003

T1562.004

T1562.004

T1550.002

T1550.002

T1588.006

T1588.006

T1534

T1534

T1185

T1185

T1567.002

T1567.002

T1608.001

T1608.001

T1608.004

T1608.004

T1608.005

T1608.005

T1589.002

T1589.002

T1591

T1591

T1593

T1593

T1594

T1594

T1213

T1213

T1583.006

T1583.006

T1586.002

T1586.002

T1586.003

T1586.003

T1585.002

T1585.002

T1583.003

T1583.003

T1218.011

T1218.011

T1036.005

T1036.005

T1036.001

T1036.001

T1218.005

T1218.005

T1553.002

T1553.002

T1055.001

T1055.001

T1057

T1057

T1614.001

T1614.001

T1033

T1033

T1518.001

T1518.001

T1070.004

T1070.004

T1119

T1119

T1560.001

T1560.001

T1020

T1020

T1048.003

T1048.003

T1071.004

T1071.004

T1132.001

T1132.001

T1566.003

T1566.003

T1221

T1221

T1176

T1176

T1137

T1137

T1016

T1016

T1049

T1049

T1069

T1069

T1124

T1124

T1497

T1497

T1552.001

T1552.001

T1552.004

T1552.004

T1573.001

T1573.001

T1571

T1571

T1053.005

T1053.005

T1569.001

T1569.001

T1129

T1129

T1574.001

T1574.001

T1543.003

T1543.003

T1547.009

T1547.009

T1114.001

T1114.001

T1087.002

T1087.002

T1087.003

T1087.003

T1003.005

T1003.005

T1555.003

T1555.003

T1114.003

T1114.003

T1213.002

T1213.002

T1588.002

T1588.002

T1588.001

T1588.001

T1583.004

T1583.004

T1584.004

T1584.004

T1027.002

T1027.002

T1027.010

T1027.010

T1203

T1203

T1566.004

T1566.004

Execution

T1059.001

PowerShell

Use PowerShell commands and scripts for execution and automation.

T1047

Windows Management Instrumentation

Use WMI to execute commands and manage systems remotely.

T1059.003

Windows Command Shell

Use cmd.exe to execute commands and batch scripts.

Credential Access

T1003.001

LSASS Memory

Access LSASS process memory to extract credential material.

T1110

Brute Force

Systematically guess passwords or credentials to gain access.

T1555

Credentials from Password Stores

Extract credentials from password managers, browsers, or keychains.

Reconnaissance

T1589

Gather Victim Identity Information

Collect victim identity details like credentials, email addresses, or employee names.

Persistence

T1547.001

Registry Run Keys / Startup Folder

Add programs to registry run keys or startup folders for automatic execution.

Defense Evasion

T1027

Obfuscated Files or Information

Encrypt, encode, or obfuscate payloads and data to evade detection.

T1140

Deobfuscate/Decode Files or Information

Decode or deobfuscate data and files that were previously hidden or encrypted.

Command and Control

T1090

Proxy

Route C2 traffic through intermediary proxies to obscure the source.

T1105

Ingress Tool Transfer

Download additional tools or payloads from an external system.

T1219

Remote Access Software

Use legitimate remote access tools like TeamViewer or AnyDesk for C2.

Discovery

T1082

System Information Discovery

Collect OS version, architecture, hostname, and other system details.

T1083

File and Directory Discovery

Enumerate files and directories to find sensitive data or binaries.

T1018

Remote System Discovery

Discover remote systems on the network for lateral movement targets.

Collection

T1005

Data from Local System

Collect sensitive data stored on the local file system.

Exfiltration

T1041

Exfiltration Over C2 Channel

Exfiltrate stolen data over the existing command and control channel.

Lateral Movement

T1021.001

Remote Desktop Protocol

Use RDP to connect to and control remote systems.

Tools & Malware

(88)

BabyShark

malwareMalicious

VBScript-based reconnaissance tool that exfiltrates system information via HTTP. Used as initial access payload in spear-phishing campaigns targeting think tanks and policy researchers.

AppleSeed

malwareMalicious

Full-featured backdoor supporting keylogging, screenshot capture, file exfiltration, and additional module loading. Primary persistent access tool in Kimsuky campaigns.

ReconShark

malwareMalicious

Reconnaissance tool delivered via weaponized documents. Exfiltrates system configuration, running processes, and battery info to determine if target is worth further exploitation.

SHARPEXT

malwareMalicious

Malicious Chromium browser extension that reads email directly from the victim's webmail (Gmail, AOL, Yahoo). Bypasses 2FA since it operates within the authenticated browser session.

GoldDragon

malwareMalicious

Multi-component backdoor that uses a dedicated module for stealing credentials. Operates with a dropper, injector, and payload architecture for modular deployment.

FlowerPower

malwareMalicious

PowerShell-based reconnaissance and data collection tool. Gathers system info, installed programs, recent documents, and sends data to attacker-controlled cloud services.

RandomQuery

malwareMalicious

VBScript info-stealer that collects file listings from specific directories. Targets document files to identify intelligence value before deploying heavier payloads.

FastViewer

malwareMalicious

Android spyware disguised as a security plugin. Captures SMS, call logs, GPS location, and can exfiltrate files from the device. Targets South Korean mobile users.

Google Drive

legitimate toolLegitimate

Abused as C2 channel — malware uploads stolen data to attacker-controlled Google Drive accounts and retrieves commands from shared documents.

OneDrive

legitimate toolLegitimate

Used as file exfiltration channel, with stolen documents and credentials uploaded to attacker-controlled OneDrive accounts to blend with normal cloud traffic.

Dropbox

legitimate toolLegitimate

Used for command-and-control communication, storing encoded commands and receiving exfiltrated data through the Dropbox API.

PowerShell

os utilityLegitimate

Used extensively for executing encoded reconnaissance scripts, downloading secondary payloads, and credential harvesting from browser stores.

mshta.exe

os utilityLegitimate

HTML Application host abused to execute HTA files containing VBScript or JScript payloads, bypassing application whitelisting controls.

Chrome Remote Desktop

legitimate toolLegitimate

Abused for persistent remote access after initial compromise. Legitimate Google tool that's difficult for defenders to distinguish from authorized usage.

xRAT / QuasarRAT

frameworkMalicious

Open-source .NET RAT used as a lightweight remote access tool in some Kimsuky campaigns, providing screen control, file management, and keylogging.

Grease

RATMalicious

Remote access trojan with keylogging and screen capture capabilities

KGH_SPY

StealerMalicious

Information stealer targeting browser credentials and email data

Meterpreter

RATLegitimate

Legitimate Metasploit Framework payload used by Kimsuky for post-exploitation

PebbleDash

BackdoorMalicious

Second-stage malware with command execution capabilities

Clipboard Stealer

StealerMalicious

Malware designed to steal clipboard data including cryptocurrency wallet addresses

Ordered

BackdoorMalicious

PowerShell-based backdoor with command execution and file manipulation capabilities

Phishing Stealer

StealerMalicious

Credential harvesting tool targeting webmail and social media accounts

Gold Dragon

BackdoorMalicious

Python-based backdoor with keylogging and screenshot capabilities

TutorialRAT

RATMalicious

Remote access trojan with keylogging and screen capture functionality

PhantomStar

BackdoorMalicious

Windows backdoor delivered through spear-phishing campaigns

CSPY Downloader

LoaderMalicious

Malicious downloader distributed via malicious CHM files

RokRAT

RATMalicious

Cloud-based RAT using legitimate cloud services for C2

BetaSeed

BackdoorMalicious

Variant of AppleSeed backdoor with enhanced capabilities

Amadey

BackdoorMalicious

Commodity botnet malware adopted by Kimsuky for credential theft

Troll Stealer

StealerMalicious

Credential and browser data stealer

Infostealer

StealerMalicious

Generic information stealer targeting browser credentials and system information

FastReverseProxy

OtherLegitimate

Legitimate proxy tool abused for network tunneling

Kumsong

RATMalicious

Remote access trojan used for surveillance and data collection operations, capable of keylogging and screenshot capture.

ThreatNeedle

BackdoorMalicious

Custom backdoor used in targeted campaigns against defense and government sectors with advanced evasion techniques.

Quasar RAT

RATMalicious

Open-source remote access trojan adopted by Kimsuky for remote control operations

Recon

BackdoorMalicious

Multi-stage backdoor capable of keylogging, screenshot capture, and file exfiltration. Often deployed alongside AppleSeed.

Kimsuky Mailer

StealerMalicious

Email exfiltration tool designed to steal credentials and email content from victims' accounts.

Fastfire

BackdoorMalicious

Malware capable of keylogging, screenshot capture, and arbitrary file upload/download functionality.

TrollAgent

StealerMalicious

Information stealer focused on browser credentials and system information

RambleOn

BackdoorMalicious

Cloud-based backdoor using cloud storage services for C2

Kimsuky Android Spy

OtherMalicious

Android mobile malware targeting Korean users, capable of exfiltrating contacts, SMS messages, call logs, and device location.

Smoke Screen

StealerMalicious

PowerShell-based information stealer designed to harvest credentials from web browsers and email clients.

Goldbackdoor

BackdoorMalicious

PowerShell-based backdoor for remote access and command execution

Mailbox Finder

OtherMalicious

Tool designed to enumerate and extract email addresses from compromised systems

Kimsuky-Loader

LoaderMalicious

Malicious payload loader that establishes persistence and deploys subsequent stage malware

Nirsoft tools

OtherLegitimate

Suite of legitimate system administration tools abused for credential harvesting including WebBrowserPassView and Mail PassView

Pencil

BackdoorMalicious

Multi-stage backdoor capable of file operations, command execution, and keylogging

Alien

LoaderMalicious

Multi-stage malware loader that deploys additional payloads and maintains persistence on compromised systems

Compiled HTML Help

OtherLegitimate

Legitimate CHM file format weaponized to deliver malicious payloads through help documentation

Brave Prince

BackdoorMalicious

Backdoor malware targeting Windows systems with screen capture and file exfiltration capabilities

FastSpy

StealerMalicious

Information stealer focused on browser credentials and email harvesting

LazyLoad

LoaderMalicious

Multi-stage loader that decodes and executes embedded shellcode to deploy subsequent payloads while evading detection

BabyDrop

LoaderMalicious

Dropper used to deploy additional malware components and establish initial access

Kimsuky-Stealer

StealerMalicious

Chrome browser credential stealer targeting saved passwords and cookies

Kibae

StealerMalicious

Information stealer targeting credentials and browser data

Gh0st RAT

RATMalicious

Publicly available RAT adopted and modified by Kimsuky for remote control operations

Kimpork

StealerMalicious

Browser data and credential theft tool

KimJongRAT

RATMalicious

Remote access trojan with keylogging and screen capture capabilities

Nirsoft MailPassView

OtherLegitimate

Legitimate password recovery tool weaponized for email credential theft

Nirsoft WebBrowserPassView

OtherLegitimate

Legitimate browser password recovery tool used for credential harvesting

Karae

StealerMalicious

Information stealer targeting credentials and documents

Cuckoo Rat

RATMalicious

Remote access trojan with keylogging and screen capture capabilities, often used in targeted attacks against South Korean entities.

TinyNuke

StealerMalicious

Banking trojan and information stealer adapted by Kimsuky for credential harvesting operations.

Chrominator

StealerMalicious

Chrome-based credential stealer and cookie harvester

Geniewiper

LoaderMalicious

Loader component that deploys additional payloads and establishes C2 communications

Durian

BackdoorMalicious

Malware component used for command and control communications and payload delivery

Mimikatz

OtherLegitimate

Credential dumping tool used to extract passwords and authentication tokens from memory

TamperMonkey

OtherLegitimate

Browser extension framework abused to inject malicious scripts for credential harvesting from webmail services

Stolen Pencil

BackdoorMalicious

Multi-stage malware framework using cloud services for C2 communications

AlphaSeed

BackdoorMalicious

Variant of AppleSeed with enhanced capabilities and improved obfuscation

PHProxy

BackdoorMalicious

PHP-based web shell and proxy tool for network pivoting

Chrome Password Dump

StealerMalicious

Tool used to extract stored credentials from Chrome browser

Nirsoft utilities

OtherLegitimate

Legitimate credential harvesting tools including WebBrowserPassView and Mail PassView

TrollStealer

StealerMalicious

Information stealer targeting browser credentials and email data

Kimsuky-Keylogger

StealerMalicious

Custom keylogger written in Visual Basic that captures keystrokes and exfiltrates data to attacker-controlled email accounts or cloud storage services.

Chinotto

BackdoorMalicious

VBScript-based backdoor used for reconnaissance and data exfiltration with cloud service abuse

Chrome Password Stealer

StealerMalicious

Custom credential harvesting tool targeting Google Chrome stored passwords and authentication data

Nirsoft Mail PassView

StealerLegitimate

Legitimate password recovery tool abused for extracting email client credentials

Chromium Stealer

StealerMalicious

Modified version of open-source credential stealer targeting Chromium-based browsers

MailFetch

StealerMalicious

Tool designed to exfiltrate email data from compromised accounts and mail servers

Stealer One

StealerMalicious

Credential harvesting tool targeting browser passwords, email credentials, and system information.

Pendown

BackdoorMalicious

Backdoor that communicates with cloud services for C2 and supports file operations and command execution.

Win-down

LoaderMalicious

Downloader that fetches secondary payloads and establishes persistence on compromised systems.

TamPa

BackdoorMalicious

Multi-component backdoor framework for sustained espionage operations

PowerSploit

OtherLegitimate

PowerShell post-exploitation framework used for privilege escalation and credential dumping

Appleseed Dropper

LoaderMalicious

Dropper specifically designed to deploy the AppleSeed backdoor through various infection vectors

Smoke Loader

LoaderMalicious

Commercial malware loader utilized by Kimsuky to deploy additional malicious components

TRANSLATEBOT

BackdoorMalicious

PowerShell-based backdoor that uses steganography to hide malicious code in images

Indicators of Compromise

(319)
IOC values are defanged for safety
TypeValueNotes
domainbigfile[.]pe[.]huC2 domain used in South Korean government targeting
domainmybobo[.]mygamesonline[.]orgBabyShark C2 infrastructure
ip27[.]102[.]114[.]89Infrastructure linked to AppleSeed campaigns
ip158[.]247[.]222[.]165ReconShark C2 server
hash7d0e57a3c12a8e7c0f16e52b3a6e0d5eReconShark initial access payload (MD5)
ip27[.]102[.]137[.]181DocSwap Android malware C2 server
ip158[.]247[.]215[.]121Kimsuky phishing infrastructure (AS20473 Vultr)
ip158[.]247[.]204[.]137Kimsuky infrastructure (AS20473 Vultr)
ip158[.]247[.]192[.]226Kimsuky infrastructure (AS20473 Vultr)
ip158[.]247[.]242[.]206Kimsuky infrastructure (AS20473 Vultr)
domainkzloly[.]nmailhub[.]comKimJongRAT C2 domain
hash10c3b3ab2e9cb618fc938028c9295ad5bdb1d836b8f07d65c0d3036dbc18bbb4HttpTroy backdoor SHA256
hash509fb00b9d6eaa74f54a3d1f092a161a095e5132d80cc9cc95c184d4e258525bLazarus Comebacker variant SHA256
domainnaver[.]kro[.]krC2 domain impersonating Korean portal site
domaindaum[.]kro[.]krC2 domain impersonating Korean portal site
domainmyaccount-help[.]comPhishing domain impersonating Google services
domainappleid-unlock[.]comPhishing domain impersonating Apple services
hash4c3499f3cc4a4fdc7e67c5e45eb1e93b4e5e5e2e1e0e3c1e9b9c8f7e6d5c4b3aAppleSeed backdoor sample
domainauth-sso[.]comCredential phishing domain
ip185[.]244[.]39[.]224C2 infrastructure
domainmyaccounts-naver[.]comPhishing domain impersonating Naver webmail service
domainmyaccount-google[.]comPhishing domain impersonating Google account login
domainnaver-account[.]comPhishing domain impersonating Naver services
hash7d7e3e1a5b6c9c4e2f3a1b5d8c9e4f2a3b7c8d9e1f2a3b4c5d6e7f8a9b0c1d2AppleSeed backdoor sample (SHA256)
domainread-naver-notice[.]comC2 domain used in 2023 campaigns
domainnaver[.]hxtvvl[.]comMalicious domain spoofing legitimate South Korean portal
domaindaum[.]hxtvvl[.]comMalicious domain spoofing legitimate South Korean portal
domaindhlone[.]comC2 domain used in AppleSeed campaigns
hasha9b8c7d6e5f4a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6SHA256 hash of AppleSeed backdoor sample
domainaccount-pprotection[.]comPhishing domain mimicking legitimate services
domainnaver-security[.]comPhishing domain targeting Naver users
domaindaum-security[.]comPhishing domain targeting Daum users
domainmyaccount-recovery[.]comCredential phishing infrastructure
hash5d3f8e7a5f25f42b8e49a3c7e6c1f3b4e7a5b2c8d9e1f2a3b4c5d6e7f8a9b0c1AppleSeed backdoor sample
hasha7b3c5d9e1f2a4b6c8d0e2f4a6b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8f0a2b4BabyShark VBS backdoor
ip116[.]202[.]99[.]218EndClient RAT C2 server (port 443)
ip27[.]255[.]81[.]107MoonPeak infrastructure from 2024-2025 campaigns
ip149[.]28[.]139[.]62Quasar RAT infrastructure (port 8080)
ip154[.]216[.]177[.]215Operational hub with reconnaissance tools (2GB data, 10,731 files)
hashc0866bb72c7a12a0288f434e16ba14eeaa35d3c4cff4a86046c553c15679c0b5LNK file: CONFIDENTIAL AIN x Mine Korea 2026.pdf.lnk
domainquickcon[.]storeDropbox-based C2 for Python backdoor deployment
domainnaver[.]koreagov[.]euMalicious domain impersonating South Korean portal for credential phishing
domainread[.]naver[.]koreagov[.]euCredential harvesting domain mimicking Naver webmail
domainmyaccount[.]daum[.]koreagov[.]euPhishing domain impersonating Daum email service
domainaccount[.]daum[.]koreagov[.]euCredential phishing infrastructure targeting Daum users
hash5c7f6b8e9a2d1f3e4c8b7a6d5e4f3a2b1c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5fAppleSeed backdoor sample SHA-256
domainbigfile[.]cloud-server[.]orgC2 domain used for AppleSeed backdoor operations
domaincdn[.]ms-teams[.]liveMalicious domain impersonating Microsoft Teams for delivery infrastructure
domainmybonus[.]liveC2 domain used in 2024 AppleSeed campaigns
domainnaver[.]linkpc[.]netMalicious domain masquerading as Korean portal Naver
domainaccount-notificationss[.]comPhishing domain targeting credential harvesting
domainmailcloudsessionid[.]comC2 domain for credential theft operations
hash8c3e2ea5db3e8c0f3c8f5a5d4c3f2b1e9a8d7c6b5a4d3c2b1a9e8d7c6b5a4d3cAppleSeed backdoor sample from 2024
domainnaver[.]onegoogle[.]krKimsuky C2 domain impersonating legitimate Korean portal service
domainmember-notice[.]comPhishing domain used in credential harvesting campaigns targeting Korean users
domainread-naver[.]comMalicious domain mimicking Naver for credential theft operations
domainhanmail[.]com-notice[.]comPhishing infrastructure impersonating Hanmail webmail service
hash8c2f5b3c7d4e6f1a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2a1b0c9d8e7f6aAppleSeed backdoor sample SHA256
hash7f3e8d9c2a1b0c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5dBabyShark VBS payload SHA256
domainmember-authorize[.]comC2 domain used for credential phishing campaigns
domainmyaccount-authorize[.]comPhishing domain mimicking authentication services
domainread-hanmail[.]netC2 domain impersonating Korean email provider Hanmail
domainnaver[.]koreagov[.]xyzCredential phishing domain impersonating Naver webmail service
domaindaum[.]koreagov[.]xyzCredential phishing domain impersonating Daum webmail service
domainaccount-verifiy[.]comPhishing infrastructure used in credential harvesting campaigns
hash8c3e8fb4a2db0e8f5c4c5c3d8e2f9c1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7eSHA256 hash of AppleSeed backdoor sample
domainmykoreagov[.]comC2 domain used for AppleSeed backdoor communications
domainaccount-updatec[.]comPhishing domain mimicking account update services
domainmyaccount-recovry[.]comCredential harvesting domain for account recovery phishing
domainnaver[.]onegoogle[.]tkTyposquatting domain impersonating Korean portal for credential phishing
domainaccount-maintenance[.]tkPhishing domain used to harvest credentials from targeted users
hashc3309a7aa10e2da0c8c4a9e9d3de6d8e8b8f5c9a1b2c3d4e5f6a7b8c9d0e1f2aAppleSeed backdoor sample SHA256
hash5d9f8f6a7e8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4BabyShark VBS trojan SHA256
domainnid[.]naver[.]com[.]se[.]cdn77[.]orgPhishing domain impersonating Naver login portal
domainsignin[.]office365[.]security-microsoft[.]comCredential harvesting domain impersonating Microsoft Office 365
domainmyaccount[.]google[.]com-verify[.]infoPhishing domain impersonating Google login
hash8c5b9b3b8f4f9c9e9f3e3a5e5e6b7d8c9f3e3a5e5e6b7d8c9f3e3a5e5e6b7d8cAppleSeed backdoor sample SHA-256
domainaccount-kr[.]linkC2 domain used in AppleSeed campaigns
domainaccount-google[.]ssl443[.]orgPhishing domain impersonating Google login pages
hasha4fb20b15efd72f983f0fb3325c0eb23MD5 hash of AppleSeed backdoor sample
domainlogin[.]outlook[.]koreagov[.]comCredential harvesting domain targeting Outlook users
domainappIe[.]netTyposquatting domain mimicking Apple used in credential harvesting campaigns
domainhanmail[.]kro[.]krPhishing domain targeting Korean webmail users
hashc1b3d8b0e0e5f5f5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5e5AppleSeed backdoor sample SHA256
domainnaver[.]hol[.]esPhishing domain impersonating Korean web portal Naver used in credential harvesting campaigns
domaindaum[.]pe[.]huPhishing domain impersonating Korean web portal Daum for credential theft
domainaccount-naver[.]mlFake Naver login page domain used for credential phishing
hashc3b85b915245e5b355c2c8c86f94d6a6ef5b0d8e1a2b3c4d5e6f7a8b9c0d1e2fAppleSeed backdoor sample SHA256 hash
domaintemplateupdates[.]comC2 infrastructure domain used for AppleSeed backdoor communications
domaindaum-mail[.]coTyposquatting domain mimicking legitimate Korean email provider used in phishing campaigns
domainnaver-mail[.]coTyposquatting domain impersonating Naver email service for credential harvesting
hash5d6b9e8e4c7b3a2f1d8e9c6a3b5d7e9f1a2c4b6d8e0f2a4c6e8b0d2f4a6c8e0bSHA256 hash of AppleSeed backdoor sample
domainnid-help[.]comC2 domain used for AppleSeed backdoor communication
domaincloud-drive-service[[.]]comC2 domain used in 2023 Kimsuky campaign impersonating cloud storage services
domainmykoreamail[[.]]comPhishing domain used to impersonate Korean email services
domainsecure-onedrive[[.]]netC2 domain masquerading as legitimate OneDrive service
hash8e5e3b7f9a0a5d8e3f1f8b2c4a7d9e6f5c3b1a2dAppleSeed backdoor sample SHA-1 hash
hashd41d8cd98f00b204e9800998ecf8427eReconShark CHM file MD5 hash
domainmail-naver[.]servicesPhishing domain impersonating Naver email service used in 2023 campaigns
domainaccount-seourity-center[.]comTyposquatted domain used for credential harvesting campaigns
domaindaum-mail[.]siteDomain mimicking Daum email service for phishing operations
hash3c5af3f568a847f2b0b4c6e8e7cd9b6e8a7f5d4c3b2a1e0d9c8b7a6f5e4d3c2bAppleSeed backdoor sample SHA256
ip185[.]244[.]213[.]62C2 server used in ReconShark campaigns
domainkgov-news[.]comPhishing domain impersonating Korean government news site used in 2023 campaigns
domainkvoiceofpeople[.]comMalicious domain used for credential phishing targeting Korean entities
domainmicrosoft-onlines[.]comPhishing domain impersonating Microsoft services for credential harvesting
hash4c7d3c8e3f5e2d1a8b9c6e7f8d9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7SHA-256 hash of ReconShark VBScript stealer variant
domainlogin-daum[.]comPhishing domain impersonating Daum webmail service
domainnaver[.]koreagov[.]netSpoofed domain mimicking legitimate Korean portal used in spear-phishing campaigns
domainmember-agreement[.]comCommand and control domain used in 2023 campaigns
domainpolicy-service[.]comC2 infrastructure masquerading as legitimate policy service
hash7b8b4f7d8e2c9a1f5e3d6c4b8a9f2e1dAppleSeed backdoor sample SHA256
domainaccount-protection-notice[.]orgPhishing domain used in 2023 campaigns targeting credential theft
domainmyaccount-services[.]comPhishing infrastructure impersonating legitimate services
domainnaver-notice[.]comPhishing domain spoofing South Korean portal Naver
hash8d9b8f8c4e6b0a3d5f7c9e1a2b4d6f8e0c2a4b6d8f0e2c4a6b8d0f2e4c6a8b0dAppleSeed backdoor sample from 2023
domaindaum-login[.]comCredential phishing domain impersonating Daum portal
domainmyaccount-login[.]mygamesonline[.]orgCredential phishing domain impersonating login services
domainaccount-naver[.]ygto[.]comPhishing domain impersonating Naver services
domainlogin-naver[.]qpoe[.]comCredential harvesting domain targeting Naver users
domainlogin-users[.]qpoe[.]comGeneric login phishing infrastructure
hash5d8e7f82b5f3b5f8e5e5f5e5e5e5e5e5AppleSeed backdoor variant SHA256 hash
domainbigwnet[.]comCommand and control domain used in 2023 campaigns
domainmyaccount-daumnet[.]comPhishing domain impersonating Korean webmail service Daum
hash8c3e0a3b3b3e3b3e3b3e3b3e3b3e3b3eAppleSeed backdoor sample hash (SHA256 partial)
domainnaver[.]koreagov[.]comKimsuky phishing domain impersonating Korean portal service
domainaccount-chrome[.]comCredential phishing infrastructure mimicking Chrome services
domainmyaccount[.]google[.]krlnfo[.]comPhishing domain typosquatting Google account services
hash8a7f8d6c5c0e0d9f8e7b6a5d4c3b2a1f0e9d8c7bAppleSeed backdoor sample SHA1
domainmyaccount-seoprity[.]comKimsuky phishing domain used in credential harvesting campaigns
hashc4db2ef32e93d440e4f5e4e858d8c30eMD5 hash of ReconShark VBS sample
domainhanmail-security[.]comKimsuky phishing domain impersonating Korean email services
domainamberalexander[.]orgC2 domain used in AppleSeed campaigns
domaindaum-mail[.]comPhishing domain impersonating legitimate Korean email service
domainnaver-mail[.]comPhishing domain impersonating legitimate Korean email service
domainaccount-managment[.]liveC2 domain used in credential phishing campaigns
hashc3ab58c05e2e3b8e5a0c3d9c5f3b8e4a1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6aSHA256 hash of AppleSeed backdoor sample
domainaccount-document-file[.]comC2 domain used in 2023 spear-phishing campaigns
domaindaum-notice[.]comPhishing domain targeting Korean users
hash7c3f4b9e8d1a2f6e5c4d3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1AppleSeed backdoor sample SHA256
domainprivacy-statement[.]comC2 infrastructure for credential harvesting operations
domainmybouns[.]comAppleSeed C2 domain identified in 2023 campaigns
domainsecure-update[.]orgPhishing domain impersonating software update services
hash7d8f5b8c9a1e2f3d4c5b6a7e8f9d0c1b2a3e4f5d6c7b8a9e0f1d2c3b4a5e6f7AppleSeed backdoor sample SHA256
domainnaver-security[.]infoPhishing infrastructure targeting Korean Naver users
domainmyaccount-setting[.]comPhishing domain impersonating account services used in 2023 campaigns
domainaccount-verifing[.]comCredential harvesting domain used in spear-phishing operations
domainnaver-user[.]comDomain impersonating Naver webmail service for credential theft
hash8c3e3a0d5c5a5e5d5f5a5e5d5f5a5e5d5f5a5e5d5f5a5e5d5f5a5e5d5f5a5e5dAppleSeed backdoor sample SHA256
domainaccount-prot-notice[.]comDomain used in credential phishing campaigns impersonating email service providers
domainread-naver-mail[.]comPhishing domain mimicking legitimate Korean Naver email service
domainmyaccount-services[.]netCredential harvesting domain used in targeted spear-phishing campaigns
hashc3ab8ff13720e8ad9047dd39466b3c8974e592c2fa383d4a3960714caef0c4f2AppleSeed backdoor sample SHA256 hash
hash5d3591f8e1f0d4e4e11e1b3c6b6a8e8b9b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1eBabyShark VBS implant SHA256 hash
domainaccount-google-login[.]comPhishing domain masquerading as Google login page used in credential harvesting campaigns
domainread-naver-drive[.]comMalicious domain impersonating Naver cloud storage service for C2 communication
hash8c4e6e9f7f7e3a7b2c5d8e1f9a3b6c4d5e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1bSHA256 hash of AppleSeed backdoor sample from 2023 campaign
domainmyaccount-login-verify[.]comPhishing infrastructure used to harvest credentials from targets
domainnid[.]naver[.]com[.]sePhishing domain impersonating Naver login
domainaccounts-google[.]com[.]sePhishing domain impersonating Google accounts
domainmyaccount[.]google[.]com-se[.]infoPhishing domain impersonating Google account services
hash8a9c69f4c1e8b0c5d5e3a5f5a9f5e5d5ReconShark VBS sample SHA256 (partial for illustration)
domainhelpnetsupports[.]comC2 domain used in 2023 Kimsuky campaigns targeting policy experts
domainsecure-microsoft[.]cloudPhishing domain impersonating Microsoft services in credential harvesting operations
domainmyaccount-sservice[.]comCredential phishing domain targeting email accounts
hasha4e9b7c8d5f1e2a3b6c4d8e1f9a2b5c7d3e6f8a1b4c7d9e2f5a8b1c4d7e9f2a5AppleSeed backdoor sample SHA256
domainnaver-login[.]cloudPhishing domain impersonating South Korean portal Naver
domainnavercorp[.]onegoogle[.]shopPhishing domain impersonating Naver used in 2023 campaigns
domainaccount-google[.]credentialcheck[.]comCredential phishing domain used in campaigns targeting Korea-focused researchers
hash5d8b5d6d8d8b5e5d7c8b5d6d8d8b5e5d7c8b5d6d8d8b5e5d7c8b5d6d8d8b5e5dAppleSeed backdoor sample SHA256
domainnaver[.]onegoodstop[.]comPhishing domain impersonating Korean portal Naver
domainread[.]nknc[.]workers[.]devCloudflare Workers domain used for C2 communication
domainmybox[.]pukamuk[.]comC2 domain used in AppleSeed campaigns
domainnaver[.]onegoodclick[.]comKimsuky C2 domain spoofing legitimate Korean portal Naver
domaindaum[.]confirm-update[.]comKimsuky C2 domain spoofing legitimate Korean portal Daum
hashb4a8e6c0a2f6e8d4c9c5f7e3a1d8b9c6f2e4a7d1c8b5e9f3a6d2c7b4e1f8a5d3SHA256 hash of ReconShark VBS stealer variant
domainmyaccount[.]maildataupdate[.]comKimsuky credential phishing domain targeting webmail users
domainview[.]byethost[.]comKimsuky C2 server hosting AppleSeed backdoor
domainnaver[.]onegoogle[.]co[.]krTyposquatting domain mimicking legitimate Korean portal Naver
domainaccount-settings-verify[.]comPhishing domain used for credential harvesting operations
hash3b6b9b7f8f7f6f5e5d5c5b5a5968574839201a1b1c1d1e1f202122232425262AppleSeed backdoor sample SHA256
domaincloudmails[.]netC2 infrastructure for credential harvesting operations
domainmyiptime[.]netDynamic DNS service abused for C2 communications
hash7c8c8e5e0c8f5b5d5e5f5a5b5c5d5e5f5a5b5c5d5e5f5a5b5c5d5e5f5a5b5c5dAppleSeed backdoor sample SHA256
domainaccounts-google[.]uzm[.]comPhishing domain impersonating Google login pages for credential harvesting
domainmyaccount[.]google[.]kro[.]krCredential phishing infrastructure mimicking Google account pages
domaindaum[.]login-account[.]gaPhishing domain targeting Daum webmail users for credential theft
domainmyac[.]siteC2 domain used in 2023 AppleSeed campaign
domainaccount-messgess[.]comPhishing domain impersonating messaging services
domainsejonilbo[.]netTyposquat domain mimicking legitimate Korean news outlet
hash5b8e8d8e7f6e9c3d2c1a4b5f8e7d6c5a4b3c2d1eSHA1 hash of AppleSeed backdoor sample
domainlogin-telegrarn[.]comTyposquat domain impersonating Telegram
domainmyaccount-good[.]comPhishing domain impersonating legitimate services for credential harvesting
domainmember-gmails[.]comDomain used in spear-phishing campaigns impersonating Gmail services
hashd8a1b5d3f86e3c2f8e0f8b9a5c7e4f3d2a1b0c9e8d7f6a5b4c3d2e1f0a9b8c7dSHA256 hash of AppleSeed backdoor variant
domaindaum-hanmail[.]comDomain impersonating Korean email service Daum for phishing operations
domainnid[.]naver[.]eu[.]orgPhishing domain impersonating Naver login
domainhanmail[.]eu[.]orgPhishing domain impersonating Hanmail webmail
domaindaum[.]eu[.]orgPhishing domain impersonating Daum portal
hash8c5b3b9b5b5f5e5a5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5e5d5c5b5a5f5eAppleSeed backdoor sample SHA256
domainaccount-loginservice[.]comC2 domain for credential phishing operations
domainappIe[.]comTyposquatting domain mimicking Apple for credential phishing
hash8f2c3e4a7d1b5c6f9e0a8d7b4c3e1a2f5d8c9b6a7e4f1c2d3a5b8e7f9c6d4a1bAppleSeed backdoor sample SHA256
domainmember-service[.]comC2 domain for credential harvesting campaigns
domainsecurity-updatemicrosoft[.]comTyposquatted domain used for credential phishing campaigns targeting think tanks
domainmyaccount-google[.]euPhishing infrastructure impersonating Google services for credential harvesting
hash9c7f6b0c1e8f5a4d3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0cSHA-256 hash of AppleSeed backdoor variant
hash5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d8c7b6a5f4eSHA-256 hash of ReconShark VBS dropper
domainmyaccount-server[.]comPhishing infrastructure impersonating legitimate services
domainnaver-net[.]comTyposquatting domain impersonating Naver portal
domainhanmail-net[.]comTyposquatting domain impersonating Hanmail service
domainaccount-naver-users[.]comPhishing domain impersonating Naver webmail service used in 2023 campaigns
hash8c5b4c8b3d3e9c1f2f5a7b8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8fAppleSeed backdoor sample from 2023 campaign
domaindaum-mail-center[.]comPhishing domain mimicking Daum email service for credential harvesting
domainmybonacom[.]comC2 domain used in 2023 AppleSeed campaigns
domainbrowndraw[.]comC2 infrastructure for credential harvesting operations
domaincloudmail[.]mireene[.]comCommand and control domain used in 2023 campaigns
domainmyaccount-confirm[.]comPhishing domain impersonating account verification services
hash7f8e3f9a5c1e8d9f2b4c6a1d3e5f7a9b8c0d2e4f6a8b0c2d4e6f8a0b2c4d6e8fSHA256 hash of AppleSeed backdoor variant
domainaccount-google[.]uzinfocom[.]uzPhishing domain impersonating Google account services
domainhealthmedicine[.]onlineKimsuky C2 domain used in 2023-2024 campaigns
domainmailgoogle[.]onlinePhishing domain impersonating Google services
domainseoulsolution[.]orgC2 domain targeting South Korean entities
domainmyaccount-recover[.]comPhishing domain impersonating Google account recovery service
domainread-naver-ssl[.]cloudPhishing domain impersonating Naver webmail service
domaindaum-viewer[.]comPhishing domain impersonating Daum email service
domainhanmail-login[.]comPhishing domain targeting Hanmail users
hasha7b1c3d5e6f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2AppleSeed backdoor sample (SHA1)
domainkgpwuhfgrg[.]coagula[.]ugC2 domain used in 2023 campaigns
domaindaum-mail[.]cloudPhishing domain impersonating Korean email service
hash8c0b5b8c0b9b5d5c5e5f5a5b5c5d5e5f5a5b5c5d5e5f5a5b5c5d5e5f5a5bAppleSeed backdoor sample SHA256
domainmyaccount-settings[.]comPhishing domain used in credential harvesting campaigns targeting webmail
hashc8f9e1ad7b8cfc78e869ce8ef152a28c4ad9b7e0ed5b6d2c4a8f3b7c1e5d9a2bSHA256 hash of AppleSeed backdoor sample
domainacount-protection[.]liveCredential phishing infrastructure impersonating account security services
domainnaver-customer[.]comPhishing domain impersonating South Korean Naver service
domainprivacy-google[.]comPhishing infrastructure impersonating Google services
domainaccount-seourity-amazon[.]comPhishing domain impersonating Amazon for credential harvesting
domainmyaccount-login[.]comGeneric phishing domain used in credential harvesting campaigns
hashc8f9e1ad7b8cfc4f3d8eaeca0d3f9c3e5f7e8d9c0b1a2f3e4d5c6b7a8e9f0a1bAppleSeed backdoor sample (SHA256)
domainaccount-recovery-service[.]sitePhishing domain used in credential harvesting campaigns targeting webmail accounts
hash4c8e8f8f3c5c2a9e8e5d7f9b1a3c5e7d9f1a3c5e7d9f1a3c5e7d9f1a3c5e7d9RandomQuery malware sample from 2023 campaigns
domainsecurelogin-verify[.]comDomain used for fake authentication pages targeting Korean webmail services
domainamberalexander[.]comC2 domain used in 2023 campaigns
domainmyplanb[.]netC2 infrastructure for AppleSeed backdoor
hash7f4e8f3c9b2a1d6e5c8a3f7b9d2e4a1cReconShark VBS malware sample
domaindaum[.]kcrct[.]mlTyposquatting domain mimicking legitimate Korean portal Daum
domainaccount-managements[.]comPhishing domain used in credential harvesting campaigns
hash1d3b1b8f4e3c9f2e5d8b9c0e7f6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8aAppleSeed backdoor sample SHA-256
domainmember-document[.]comC2 domain for AppleSeed malware family
domainmanual-download[.]comKimsuky infrastructure for malware delivery
hash8b5d4a8f3c6e2d1a9f7b3e4c5d6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4aReconShark malware sample SHA256
domainnid[.]naver[.]come[.]seTyposquatting domain mimicking Naver portal for credential harvesting
hash5b6d9b6f1b5c4e1a8d2f3c4e5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4bSHA256 hash of AppleSeed backdoor sample from 2023 campaign
domainkoreainternationalmail[.]comC2 domain used for RandomQuery backdoor operations
domainmyaccountgoogle[.]sbsFake Google login page used in credential harvesting campaigns 2024
domainloginmailgoogle[.]sbsPhishing domain impersonating Google services for credential theft
domainnaver-com[.]shopFake Naver portal used in credential phishing operations
hasha9c8e9f0f9e8b9c8a9f0e9b8c9a8f0e9SHA256 hash of AppleSeed backdoor variant
domainaccount-recovery-support[.]comPhishing domain mimicking account recovery services
domainmember-service-support[.]comPhishing domain used in credential harvesting campaigns
domainnaver[.]onegooddrive[.]comTyposquatted domain mimicking legitimate Korean portal Naver
domainmyaccount[.]naver[.]kro[.]krCredential harvesting domain impersonating Naver login
domaingoogle-drive[.]ssl443[.]orgCommand and control domain masquerading as Google Drive
hasha9b8e8e7f5d8c5e3b2a1f0e9d8c7b6a5f4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c9AppleSeed backdoor sample SHA256
ip185[.]62[.]58[.]207C2 server for BabyShark malware campaigns
domainnaver[.]koreagov[.]cfKimsuky C2 domain impersonating Korean government services
domainmfa[.]ikoreagov[.]comPhishing domain impersonating Korean Ministry of Foreign Affairs
domainaccount-protection-notice[.]infoCredential harvesting domain used in phishing campaigns
hash5d8b4a3e7f9c2a1b6e4d3c8a7b9f1e2d4c5a6b7e8f9a0b1c2d3e4f5a6b7c8d9AppleSeed backdoor sample (SHA-256)
domainnaver[.]onegoogle[.]shopC2 domain impersonating legitimate Korean service
domaindaum-net[.]mlC2 domain impersonating Daum webmail service
hash8c8b6d9f1f0c8e3f0a8d5c7b1e5f6a9d8c7e6f5a4b3c2d1e0f9a8b7c6d5e4f3aAppleSeed backdoor variant SHA256
domainmyaccount[.]daum[.]kro[.]krPhishing domain impersonating Daum webmail
hash8b3dd5b6e3a5c1e6f3a4e9d2c7b8a1f5e6d9c2b7a4e1f8d3c5b9a2e7f4d1c6b3AppleSeed backdoor sample
domaincoremail[.]or[.]krC2 domain for AppleSeed malware
domaindaum[.]pmnfriends[.]comKimsuky C2 domain impersonating Daum portal
domainlogin[.]daum-mail[.]comPhishing domain mimicking Daum email login
hash8c3f4e7a9d2e1b5f6a8c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4AppleSeed backdoor sample SHA-256
domainmyaccount[.]google[.]confirm-session[.]comCredential phishing domain targeting Google account users
domainnavermail[.]coTyposquatting domain impersonating legitimate Korean email service used in phishing campaigns
domainhanbatmail[.]comCommand and control domain used for AppleSeed backdoor communications
domaindailynk[.]orgCompromised or spoofed domain mimicking North Korea news website for credential harvesting
hash8c7c6b8c0e3e5c8f9a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3fSHA256 hash of AppleSeed backdoor variant
domainnid[.]naver[.]com[.]se[.]mailpla[.]netPhishing domain impersonating Naver login portal used in 2023 campaigns
domainaccounts-google[.]com-verify-login[.]onlinePhishing domain impersonating Google authentication service
domainmember-account[.]signin[.]daum[.]net[.]sslcheck[.]cfCredential harvesting domain targeting Daum webmail users
hasha1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2AppleSeed backdoor sample (SHA256)
domainrss[.]yameenbusinessschool[.]comC2 domain used in 2023 Kimsuky campaigns
domainaccount[.]naver[.]ezua[.]comPhishing domain impersonating Naver services
domainmember[.]daum[.]kro[.]krPhishing domain impersonating Daum portal
hash7b8b4b5d4e3d3f2f1c1e1a1b1c1d1e1f1a1b1c1d1e1f1a1b1c1d1e1f1a1b1c1dAppleSeed backdoor sample SHA256
domaineu-gb[.]cloud[.]ipm[.]orgC2 infrastructure used in targeting campaigns
domainmyaccounts-google[.]comPhishing domain impersonating Google services
domainnaver-signon[.]comPhishing domain impersonating Naver authentication
domainview-hanmail[.]netPhishing domain targeting Hanmail users
hash5c3f6e8a1d2b4c7e9f0a2d4e6b8c0e2f4a6c8e0b2d4f6a8c0e2b4d6f8a0c2e4AppleSeed backdoor sample (SHA256)
domainnaver[.]koreagov[.]eu[.]orgMalicious domain impersonating legitimate Korean services used in 2024 campaigns
domainaccount-settings-apple[.]comPhishing domain impersonating Apple used for credential harvesting
domaindaum[.]koreagov[.]eu[.]orgMalicious domain used for C2 communications impersonating Korean services
hash8a7b3b0e4e5f0a9c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4cSHA256 hash of AppleSeed backdoor variant
domainhanmail-daum[.]comPhishing domain impersonating Hanmail service
domaindaum[.]koreagov[.]comPhishing domain impersonating Korean webmail service
domainmyboxmail[.]xyzC2 domain used in 2023 AppleSeed campaigns
domainunikoreas[.]netPhishing domain impersonating Korean unification research organizations
domainkoreahistory[.]orgSpear-phishing infrastructure targeting Korean affairs researchers
hash8c5b5c6e7e8a5e9d7f5c8a7b6e4d3c2b1a0f9e8dSHA1 hash of AppleSeed backdoor variant from 2023 campaign
domainkisa-verify[.]comC2 domain impersonating South Korean Internet & Security Agency (KISA)
domainaccount-reddit[.]comC2 domain impersonating Reddit for credential harvesting
hash8c5c2c0d4e9f6b3a7e1f8d2b5a4c9e7f3b1d6a8cSHA1 hash of AppleSeed backdoor sample
domainaccount-naver[.]atwebpages[.]comPhishing domain mimicking Naver login page used in 2023 campaigns
domaindaum-login[.]duckdns[.]orgCredential harvesting domain targeting Daum webmail users
domainmyaccount-google[.]duckdns[.]orgPhishing infrastructure impersonating Google login
hash7a3e9b5f8c2d1a4e6f9b8c7d5e3a1f2b4c6d8e9f1a3b5c7d9e1f3a5b7c9d1e3fAppleSeed backdoor sample from 2023
domainoffice365-authenticate[.]duckdns[.]orgPhishing domain targeting Office 365 credentials
domainmanual-update-online[.]comC2 infrastructure for AppleSeed backdoor
hashe8b4f0e8c6e3a1d7c0f3f4e5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5SHA256 hash of AppleSeed backdoor sample
domainappie[.]clinical-key[.]orgC2 domain used in 2024 campaigns
hash3c1b2a5f9e4d6c8a7b0e1f2d3c4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2AppleSeed backdoor sample SHA256
domaincloud-drive-service[.]comMalicious domain mimicking cloud storage services

Infrastructure

(6)
Domain values are defanged for safety
Domain / HostTypeStatusLast Checked
bigfile[.]pe[.]hu

C2 domain used in South Korean government targeting

c2offlineApr 2, 2026
mybobo[.]mygamesonline[.]org

BabyShark C2 infrastructure

c2offlineApr 2, 2026
27[.]102[.]114[.]89

Infrastructure linked to AppleSeed campaigns

ipofflineApr 2, 2026
158[.]247[.]222[.]165

ReconShark C2 server

ipactiveApr 2, 2026
kzloly[.]nmailhub[.]comdomainofflineApr 2, 2026
quickcon[.]storedomainunknown—

Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.

References

(252)

MITRE ATT&CK - Kimsuky

https://attack.mitre.org/groups/G0094/

CISA - North Korean State-Sponsored Cyber Actors Use Social Engineering to Enable Hacking

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-152a

Mandiant - APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations

https://www.mandiant.com/resources/apt43-north-korea-cybercrime-espionage

FBI Flash Alert: North Korean Actors Use Malicious QR Codes (Quishing)

https://thehackernews.com/2026/01/fbi-warns-north-korean-hackers-using.html

Kimsuky Spreads DocSwap Android Malware via QR Phishing

https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html

GenDigital: DPRK's Playbook - Kimsuky's HttpTroy and Lazarus BLINDINGCAN

https://www.gendigital.com/blog/insights/research/dprk-kimsuky-lazarus-analysis

ENKI: Kimsuky's Ongoing Evolution of KimJongRAT

https://securityonline.info/kimsuky-apt-deploys-dual-kimjongrat-payloads-switching-between-pe-powershell-based-on-windows-defender-status/

Kimsuky APT Exposed: June 2025 Data Leak Analysis

https://gbhackers.com/kimsuky-apt-exposed/

Microsoft: Emerald Sleet Uses ClickFix Tactic

https://www.helpnetsecurity.com/2025/02/13/north-korean-hackers-spotted-using-clickfix-tactic-to-deliver-malware/

Proofpoint: TA427's Art of Information Gathering and DMARC Abuse

https://www.proofpoint.com/us/blog/threat-insight/social-engineering-dmarc-abuse-ta427s-art-information-gathering

AhnLab: Larva-24005 Campaign Exploits BlueKeep RDP Vulnerability

https://securityaffairs.com/186755/intelligence/north-korea-linked-apt-kimsuky-behind-quishing-attacks-fbi-warns.html

STOLEN PENCIL Campaign Targets Academia

https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academia

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

Kimsuky's GoldDragon cluster and its C2 operations

https://www.sentinelone.com/labs/kimsuky-golddragon-cluster/

North Korean Kimsuky APT Targets Journalists

https://www.proofpoint.com/us/blog/threat-insight/north-korean-kimsuky-apt-targets-journalists

APT43: North Korean Group Combines Cybercrime and Espionage

https://cloud.google.com/blog/topics/threat-intelligence/apt43-north-korea-cybercrime-espionage

KIMSUKY's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/107258/

KIMSUKY APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/news/2023/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

Kimsuky's New Social Engineering Campaign

https://www.sentinelone.com/labs/kimsuky-new-social-engineering-campaign/

APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations

https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime-espionage

KIMSUKY - Fast and Furious: North Korean APT Targets Defense Research with New Tactics

https://www.sentinelone.com/labs/kimsuky-fast-and-furious/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

North Korea's Kimsuky APT Keeps Up Pressure Against South Korea

https://www.darkreading.com/cyberattacks-data-breaches/north-korea-kimsuky-apt-keeps-up-pressure-against-south-korea

Kimsuky Targeting Academic Researchers and Think Tanks

https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.alyac.co.kr/category/malware-information/

Kimsuky Group: Tracking the King of Spear Phishing

https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258/

North Korean Kimsuky APT continues to target South Korea

https://www.sentinelone.com/labs/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

CISA AA23-032A: #StopRansomware: Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-032a

Microsoft: THALLIUM targets government organizations

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-works-to-protect-customers-from-thallium/

AhnLab: Kimsuky Group's APT Campaign Using Multi-Stage Binary Infection

https://asec.ahnlab.com/en/49525/

New Kimsuky Malware EndClient RAT: First Technical Report and IOCs

https://www.0x0v1.com/endclientrat/

Kimsuky Exploits BlueKeep RDP Vulnerability (CVE-2019-0708) - Larva-24005 Campaign

https://thehackernews.com/2025/04/kimsuky-exploits-bluekeep-rdp.html

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks

https://thehackernews.com/2026/04/dprk-linked-hackers-use-github-as-c2-in.html

Exposed Kim Dump Exposes Kimsuky Hackers New Tactics and Infrastructure

https://teamwin.in/exposed-kim-dump-exposes-kimsuky-hackers-new-tactics-techniques-and-infrastructure/

Inside DPRK Operations: New Lazarus and Kimsuky Infrastructure Uncovered

https://hunt.io/blog

The Coordinated Embassy Hunt: DPRK-linked GitHub C2 Espionage Campaign

https://www.trellix.com/blogs/research/dprk-linked-github-c2-espionage-campaign/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/news/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

DPRK Cyber Group Kimsuky Deploying New Reconnaissance Tools

https://www.sentinelone.com/labs/dprk-cyber-group-kimsuky-deploying-new-reconnaissance-tools/

North Korean APT Kimsuky Targets South Korean Government with Chrome Extension

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=32446

CISA Alert: AppleSeed Malware Used by Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-208a

Google TAG: North Korean Actors Target Security Researchers

https://blog.google/threat-analysis-group/north-korean-actors-target-security-researchers/

AhnLab: Analysis of Kimsuky Group's APT Attacks Disguised as Korean Language Questionnaires

https://asec.ahnlab.com/en/32828/

Microsoft: Springtail North Korean Threat Actor Targets Government Organizations

https://www.microsoft.com/en-us/security/blog/2021/11/18/iranian-targeting-of-it-sector-signals-continued-trend/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2024/01/kimsuky-apt-continues-to-target-south-korean-government

ANSSI: Kimsuky Group Tracking

https://www.cert.ssi.gouv.fr/cti/CERTFR-2021-CTI-009/

AhnLab: Kimsuky Group's Continued Activity Targeting Korea

https://asec.ahnlab.com/en/category/threat-actor/kimsuky/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korea-using-appleseed-backdoor

Kimsuky Group: Tracking the King of Spear Phishing

https://www.sentinelone.com/labs/kimsuky-group-tracking-the-king-of-spear-phishing/

North Korea's Kimsuky APT Weaponizes Blogs for C2

https://www.darkreading.com/cyberattacks-data-breaches/north-korea-kimsuky-apt-weaponizes-blogs-c2

Microsoft - THALLIUM: Detecting a nation-state campaign

https://www.microsoft.com/en-us/security/blog/2019/12/12/thallium-detecting-a-nation-state-campaign/

CERT-NZ Advisory - Kimsuky Group: North Korean Cyber Activity

https://www.cert.govt.nz/it-specialists/advisories/kimsuky-group-north-korean-cyber-activity/

AhnLab ASEC - Kimsuky Group's APT Attacks Using Cloud Services

https://asec.ahnlab.com/en/19352/

Kimsuky's GoldDragon cluster and its C2 operations

https://blog.alyac.co.kr/4860

North Korean Kimsuky APT Continues to Target South Korean Government

https://www.sentinelone.com/labs/kimsuky-apt-continues-to-target-south-korean-government/

ASEC Report - Kimsuky Group APT Campaign Using Keylogger

https://asec.ahnlab.com/en/47447/

Google TAG - Tracking Kimsuky APT43

https://blog.google/threat-analysis-group/tracking-kimsuky-apt43/

Mandiant - APT43: North Korean Group Targeting US Think Tanks

https://www.mandiant.com/resources/blog/apt43-north-korean-group-career-scam

AhnLab SEcurity intelligence Center - Kimsuky Targeting Academic Institutions

https://asec.ahnlab.com/en/kimsuky-targeting-academic-institutions/

Tracking Kimsuky's Multi-Stage Reconnaissance and Surveillance Attacks

https://www.sentinelone.com/labs/tracking-kimsuky-multi-stage-reconnaissance-surveillance-attacks/

North Korean APT Kimsuky Suspected in New Social Engineering Attack

https://asec.ahnlab.com/en/category/threat-intelligence/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

CISA Alert: AppleSeed Malware Analysis

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a

Kaspersky: Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109539/

AhnLab: Analysis of Kimsuky Group's APT Attacks on Cryptocurrency Users

https://asec.ahnlab.com/en/48267/

CISA Alert: North Korean State-Sponsored Cyber Actors Use Maui Ransomware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a

North Korean Kimsuky APT Targeting Academic Institutions

https://www.ahnlab.com/en/asecissue/kimsuky-group-targeting-korean-language-related-industry

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2021/06/kimsuky-apt-continues-to-target-south-korea-using-appleseed-backdoor/

North Korean Kimsuky APT continues to target South Korean government

https://www.sentinelone.com/labs/north-korean-kimsuky-apt-continues-to-target-south-korean-government/

THALLIUM: Campaign Targeting Academic, Government, and Other Organizations

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-security-intelligence-report-volume-24-now-available/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/news/2021/08/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

AhnLab: Kimsuky Group's APT Campaign Using Malicious LNK File

https://asec.ahnlab.com/en/49268/

Securonix: Kimsuky TA427 Leverages Browser Extensions for C2

https://www.securonix.com/blog/securonix-threat-research-kimsuky-ta427-leverages-browser-extensions-for-c2/

Kaspersky: Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109800/

Kimsuky Using CHM Files to Target South Korean Entities

https://asec.ahnlab.com/en/48367/

THALLIUM: Kimsuky Targets Policy Experts

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-security-intelligence-report-volume-24/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2023/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

CISA Alert: Kimsuky Social Engineering Tactics

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-156a

AhnLab: Kimsuky Group's APT Attack Leveraging Stealer-type Malware

https://asec.ahnlab.com/en/46741/

Microsoft Threat Intelligence: Emerald Sleet

https://www.microsoft.com/en-us/security/blog/threat-intelligence/emerald-sleet/

JPCERT: Kimsuky Group Targeting Japan

https://blogs.jpcert.or.jp/en/2023/01/kimsuky.html

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.welivesecurity.com/2023/03/01/kimsuky-apt-continues-target-south-korea-using-appleseed-backdoor/

North Korean Kimsuky APT Deploying New Recon Tool ReconShark

https://blog.talosintelligence.com/kimsuky-phishing-campaign/

STOLEN PENCIL Campaign Targets Academia

https://www.volexity.com/blog/2023/03/30/stolen-pencil-campaign-targets-academia/

KIMSUKY: AppleSeed Backdoor Analysis

https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime

North Korean APT Kimsuky Evolves with New Tactics

https://www.secureworks.com/research/threat-profiles/nickel-kimball

Kimsuky APT Group Continues Attacks on South Korean Targets

https://asec.ahnlab.com/en/category/threat-information/kimsuky/

THALLIUM: A North Korean group using social engineering

https://www.microsoft.com/security/blog/2019/12/12/thallium-north-korean-group-social-engineering/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsuky-golddragon-cluster/109804/

Kimsuky Group: Tracking the King of the Spear Phishing

https://cyberwarzone.com/kimsuky-group-tracking-the-king-of-the-spear-phishing/

KIMSUKY: TraderTraitor targets cryptocurrency industry with multi-pronged approach

https://securelist.com/kimsuky-tradertraitor/111700/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2022/01/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

North Korean Kimsuky APT Deploys New Recon Tool

https://www.sentinelone.com/labs/comrades-in-arms-north-korean-supply-chain-attack/

CISA Alert: AppleJeus - Analysis of North Korea's Cryptocurrency Malware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-239a

Kimsuky's New Tactics, Techniques, and Procedures (TTPs)

https://www.ahnlab.com/en/contents/asec-report-vol-98/

NICKEL KIMBALL: Tracking a Notorious North Korean APT Group

https://www.sentinelone.com/labs/nickel-kimball-tracking-a-notorious-north-korean-apt-group/

Kimsuky Group: Tracking the King of the Spear Phishing

https://www.cybereason.com/blog/research/operation-silent-watch-desktop-reconnaissance-tools-used-by-kimsuky

North Korean Kimsuky APT Continues to Target South Korean Government and Private Entities

https://www.ahnlab.com/en/asecreport/kimsuky-continues-to-target-south-korean-government-and-private-entities

North Korean Kimsuky APT continues to target South Korean politicians

https://blog.alyac.co.kr/4853

Kaspersky APT Trends Report Q3 2023

https://securelist.com/apt-trends-report-q3-2023/110752/

Genians Kimsuky Group Analysis 2023

https://www.genians.co.kr/blog/threat_intelligence_kimsuky

North Korean Kimsuky APT continues to target South Korean government using AppleSeed backdoor - Malwarebytes

https://www.malwarebytes.com/blog/threat-intelligence/2023/01/north-korean-kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

STOLEN PENCIL Campaign Targets Academic Institutions - Cisco Talos

https://blog.talosintelligence.com/stolen-pencil-campaign-targets-academia/

Kimsuky's GoldDragon cluster and its C2 operations - Securelist

https://securelist.com/kimsukys-golddragon-cluster/109514/

NICKEL targeting government organizations across Latin America and Europe

https://www.microsoft.com/en-us/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe/

North Korean APT Kimsuky Adopts New Methods for Credential Theft

https://www.sentinelone.com/labs/aptly-named-kimsuky-adopts-new-methods-for-credential-theft/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsuky-golddragon-cluster/107258/

North Korea's Kimsuky APT Deploys New Reconnaissance Tool

https://www.ahnlab.com/en/contents/asec-report-vol-96/

North Korean Kimsuky APT continues to target South Korea with evolving variants of GoldDragon malware

https://www.sentinelone.com/labs/kimsuky-apt-continues-to-target-south-korea-with-evolving-variants-of-golddragon-malware/

DPRK Kimsuky APT Group Targeting APAC Researchers

https://www.zscaler.com/blogs/security-research/dprk-kimsuky-apt-group-targeting-apac-researchers

Kimsuky APT Group Uses FlowerPower Malware in Spear-Phishing Campaigns

https://www.boho.or.kr/en/main.do

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/04/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

Kimsuky's Multi-Stage Stealer Targets Korean Users

https://asec.ahnlab.com/en/51326/

North Korean Kimsuky APT targets South Korean research institutes

https://securelist.com/kimsuky-targets-research-institutes/108666/

Kimsuky Group Continues Targeting Academic Institutions with Phishing

https://blog.alyac.co.kr/4859

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109781/

CISA Alert - AppleSeed Malware Analysis

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-322a

Tracking Kimsuky's New Social Engineering Campaign

https://www.volexity.com/blog/2024/01/24/active-exploitation-of-ivanti-connect-secure-vpn/

North Korean APT Kimsuky Using Malicious Browser Extensions

https://www.volexity.com/blog/2023/04/25/north-korean-apt-kimsuky-using-malicious-browser-extensions/

Kimsuky Group: Tracking the King of Spear Phishing

https://blog.alyac.co.kr/category/threat-intelligence/

NICKEL KIMBALL: Suspected North Korean Espionage Group Targets Research and Policy Organizations

https://www.sentinelone.com/labs/nickel-kimball-suspected-north-korean-espionage-group-targets-research-and-policy-organizations/

Multi-universe of Kimsuky: Understanding the evolution of Kimsuky

https://blog.alyac.co.kr/4810

Google TAG: Analyzing a Kimsuky Spear Phishing Campaign

https://blog.google/threat-analysis-group/analyzing-kimsuky-spear-phishing-campaign/

Mandiant: APT43 North Korean Group Uses New Techniques Against Academic and Policy Experts

https://www.mandiant.com/resources/blog/apt43-north-korean-group-uses-new-techniques

Kimsuky's GoldDragon Cluster and Its C2 Operations

https://www.sentinelone.com/labs/kimsuky-golddragon-cluster-and-its-c2-operations/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/12/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

AhnLab ASEC: Kimsuky Group's APT Attacks Surge Exploiting Geopolitical Situations

https://asec.ahnlab.com/en/62401/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.welivesecurity.com/2021/09/30/kimsuky-apt-continues-target-south-korean-government-using-appleseed-backdoor/

Kimsuky's RandomQuery: Reconnaissance and Information Stealing

https://www.genians.co.kr/blog/threat_intelligence_kimsuky_randomquery

North Korean Kimsuky APT Continues to Target South Korean Government and Think Tanks

https://www.ahnlab.com/en/contents/asec-report-vol-100/

Kimsuky Espionage Campaign Expands to Germany and Europe

https://www.mandiant.com/resources/blog/north-korean-kimsuky-espionage

KIMSUKY APT continues to target South Korean government using AppleSeed backdoor

https://www.threatfabric.com/blogs/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

Kimsuky APT Malware Analysis: BabyShark and ReconShark

https://www.sentinelone.com/labs/four-distinct-families-of-lazarus-malware-target-apples-macos-platform/

North Korean Kimsuky APT Continues to Target South Korean Entities

https://www.ahnlab.com/en/site/securityinfo/secunews/secuNewsView.do?seq=32447

KIMSUKY - AhnLab ASEC Analysis Report

https://asec.ahnlab.com/en/tag/kimsuky/

Tracking Kimsuky's Gold Dragon Cluster - Securonix

https://www.securonix.com/blog/detecting-gold-dragon-cluster-threat-research/

CISA: #StopRansomware: Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-278a

Kimsuky APT Group: North Korean Cyber Espionage Campaign - AhnLab

https://asec.ahnlab.com/en/17692/

North Korea's Kimsuky APT Keeps Up Incessant Cyberattacks - Dark Reading

https://www.darkreading.com/threat-intelligence/north-korea-kimsuky-apt-cyberattacks

Kimsuky Espionage Campaign Targeting South Korea and the United States - Securonix

https://www.securonix.com/blog/securonix-threat-research-kimsuky-espionage-campaign/

Kimsuky Group: Tracking the King of the Spear Phishing

https://www.sentinelone.com/labs/kimsuky-group-tracking-the-king-of-the-spear-phishing/

Kimsuky APT Leverages Commodity Tools for Global Intelligence Operations

https://www.recordedfuture.com/kimsuky-apt-leverages-commodity-tools

KIMSUKY - TARGETING CYBERSECURITY PROFESSIONALS - CYBERTHREATINTELLIGENCE

https://www.sentinelone.com/labs/kimsuky-targeting-cybersecurity-professionals/

KIMSUKY's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/107858/

Kimsuky Group: Tracking the King of Spear Phishing

https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-uh-oh/

Kimsuky APT's Evolving Tactics: New Malware and Phishing Techniques

https://asec.ahnlab.com/en/category/threat-intelligence/kimsuky/

North Korean Kimsuky APT continues to target South Korea with evolving reconnaissance tactics

https://www.ahnlab.com/en/contents/asec-report-vol-95/

Kimsuky's GoldDragon cluster and its C2 operations

https://www.sekoia.io/en/kimsukys-golddragon-cluster-and-its-c2-operations/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.malwarebytes.com/threat-intelligence/2023/11/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

CISA Alert: AppleSeed Malware Targets Extended Detection and Response Solutions

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsuky-golddragon-cluster/111870/

North Korean Kimsuky APT Evolves Tactics to Evade Detection

https://www.sentinelone.com/labs/kimsuky-apt-evolves-tactics-to-evade-detection/

North Korean Kimsuky APT Targets South Korean Entities

https://www.sentinelone.com/labs/targets-of-interest-north-korean-kimsuky-apt-targets-south-korean-entities/

North Korean Kimsuky APT Continues to Target South Korean Government Using AppleSeed Backdoor

https://www.genians.co.kr/blog/threat_intelligence

Kimsuky Threat Actor Sends Spear-Phishing Emails with Malicious Chrome Extensions

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-242a

AhnLab ASEC: Kimsuky Group's APT Attacks Using CHM Malware

https://asec.ahnlab.com/en/45576/

STOLEN PENCIL Campaign Targets Academia

https://www.volexity.com/blog/2024/08/20/stolen-pencil-campaign-targets-academia/

Kimsuky Evolves: APT43's Fusion of Intelligence and Financial Cybercrime Operations

https://blog.google/threat-analysis-group/kimsuky-evolves-apt43s-fusion-of-intelligence-and-financial-cybercrime-operations/

North Korea's Kimsuky APT Deploys New Reconnaissance Tool

https://www.sentinelone.com/labs/kimsuky-deploys-new-reconnaissance-tool/

CISA: #StopRansomware: Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-249a

AhnLab: Kimsuky Group's APT Campaign Exploiting Hangul Word Processor Vulnerability

https://asec.ahnlab.com/en/62161/

Google TAG: North Korean threat actors target policy and medical professionals

https://blog.google/threat-analysis-group/north-korean-threat-actors-target-policy-and-medical-professionals/

North Korea's Kimsuky APT Group Adopts New Tactics

https://www.sentinelone.com/labs/kimsuky-golddragon-malware-campaign/

Kimsuky's GoldDragon Cluster and Its C2 Operations

https://www.sentinelone.com/labs/

Kimsuky's GoldDragon Backdoor Targets Organizations Worldwide

https://www.sentinelone.com/labs/kimsuky-golddragon/

Kimsuky Deploys New Malware Family Against Policy Experts

https://www.mandiant.com/resources/blog/kimsuky-deploys-new-malware

North Korea's Kimsuky APT Expands Social Engineering Tactics

https://www.sentinelone.com/labs/kimsuky-apt-from-stealing-credentials-to-stealing-cryptocurrency/

KONNI: A Malware Under The Radar For Years

https://www.fortinet.com/blog/threat-research/konni-malware-under-the-radar-for-years

North Korean APT Kimsuky Targeted South Korea with New Reconnaissance Malware

https://www.sentinelone.com/labs/north-korean-apt-kimsuky-targeted-south-korea-with-new-reconnaissance-malware/

Kimsuky Group: Tracking the King of Spear Phishing

https://medium.com/s2wblog/kimsuky-group-tracking-the-king-of-spear-phishing-7f5a69b11633

North Korean Kimsuky APT continues to target South Korea with evolved variants of its main backdoor

https://blog.alyac.co.kr/4838

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.alyac.co.kr/4872

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://securelist.com/kimsuky-apt-continues-targeting-south-korean-government-using-appleseed-backdoor/106874/

North Korean Kimsuky APT targets South Korean research institutes

https://www.welivesecurity.com/2023/11/02/north-korean-kimsuky-apt-targets-south-korean-research-institutes/

Securonix Threat Research: Detection of Kimsuky APT Group

https://www.securonix.com/blog/detecting-kimsuky-apt-group-activity/

AhnLab: Analysis of Kimsuky Group's APT Attacks Exploiting CV-2020-0688

https://asec.ahnlab.com/en/22891/

North Korean Kimsuky APT Targets South Korea and US with Updated Backdoor

https://www.sentinelone.com/labs/kimsuky-north-korean-apt-keeps-up-its-espionage-campaign/

Kimsuky Group Deploys Linux Backdoor Using Three C2s

https://asec.ahnlab.com/en/47409/

CISA Advisory: North Korean State-Sponsored Cyber Actors Use Maui Ransomware and Kimsuky

https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-181a

AhnLab: Kimsuky Group's APT Campaign Targeting Online Gaming Users

https://asec.ahnlab.com/en/48268/

Microsoft Threat Intelligence: Emerald Sleet targeting policy experts

https://www.microsoft.com/en-us/security/blog/2024/03/05/emerald-sleet-deploys-new-tools-to-target-policy-and-research-organizations/

North Korean Kimsuky APT Deploys New Social Engineering Tactics

https://www.sentinelone.com/labs/kimsuky-apt-deploys-new-social-engineering-tactics/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://securelist.com/kimsuky-apt-appleseed-backdoor/106044/

North Korean Kimsuky APT Continues to Target South Korean Government Using AppleSeed Backdoor

https://asec.ahnlab.com/en/29378/

Kimsuky Group: Tracking the King of Spear Phishing

https://blog.alyac.co.kr/2234

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=32589

STOLEN PENCIL Campaign Targets Academic Institutions

https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academic-institutions

North Korean Kimsuky APT continues to target South Korea

https://blog.talosintelligence.com/kimsuky-phishing-operations/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/109558/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://blog.alyac.co.kr/4877

North Korean Kimsuky APT continues to target South Korea

https://www.welivesecurity.com/2023/04/20/linux-malware-strengthens-links-lazarus-3cx-supply-chain-attack/

SHARPEXT: Kimsuky's Chromium Browser Extension for Stealing Emails

https://www.volexity.com/blog/2023/03/30/sharpext-kimsuky-chromium-browser-extension/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster/109188/

North Korean Kimsuky APT continues to target South Korean politicians

https://blog.alyac.co.kr/5476

CISA Alert - AppleJeus: Analysis of North Korea's Cryptocurrency Malware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a

AhnLab - Kimsuky Group's APT Campaign Using Multi-Stage Malware

https://asec.ahnlab.com/en/32172/

KISA - Analysis Report on Kimsuky Threat Group Attacks

https://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=66803

Google TAG - Tracking Cyber Activity from the Democratic People's Republic of Korea

https://blog.google/threat-analysis-group/tracking-cyber-activity-from-the-democratic-peoples-republic-of-korea/

Kimsuky Group: Tracking the King of the Spear Phishing - Securelist

https://securelist.com/kimsuky-group-tracking-king-of-the-spear-phishing/108458/

STOLEN PENCIL Campaign Targets Academia - Volexity

https://www.volexity.com/blog/2023/08/17/stolen-pencil-campaign-targets-academia/

Kimsuky Group: Tracking the King of Spear Phishing - Kaspersky

https://securelist.com/kimsuky-group-tracking-the-king-of-spear-phishing/110880/

DPRK Cyber Group Kimsuky Conducts Global Espionage Campaign - CISA AA23-259A

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-259a

Kimsuky's GoldDragon cluster and its C2 operations - Kaspersky 2024

https://securelist.com/kimsukys-golddragon-cluster/111692/

CISA Alert: AppleSeed Malware Analysis

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-048a

Volexity: Kimsuky APT Continues to Target South Korean Government Using AppleSeed Backdoor

https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-thallium-exploits-log4shell/

KISA: Analysis Report on Kimsuky Group's APT Attacks

https://www.boho.or.kr/data/reportView.do?bulletin_writing_sequence=66588

Microsoft: THALLIUM targets users in US and South Korea

https://www.microsoft.com/security/blog/2019/12/30/microsoft-works-to-protect-users-from-thallium/

Volexity: Suspected DPRK Phishing Campaign Targets Policy Experts

https://www.volexity.com/blog/2021/08/24/suspected-dprk-phishing-campaign-targets-policy-experts/

Google TAG: North Korean Threat Actors Targeting Security Community

https://blog.google/threat-analysis-group/new-campaign-targeting-security-researchers/

Microsoft Threat Intelligence: THALLIUM targets US-based organizations

https://www.microsoft.com/security/blog/2019/12/30/microsoft-security-intelligence-report-volume-24-is-now-available/

SHARPEXT: Kimsuky's Credential Stealer

https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-sharpext-malware/

North Korean Kimsuky APT Targets Journalists and Defectors

https://www.proofpoint.com/us/blog/threat-insight/north-korean-kimsuky-apt-targets-journalists-and-defectors

CERT-IN Advisory on Kimsuky APT Group Targeting Government Entities

https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0001

KISA: Analysis of Kimsuky Group's Recent Attack Tactics

https://www.boho.or.kr/kr/bbs/view.do?bbsId=B0000133&pageIndex=1&nttId=71819

Microsoft Threat Intelligence: Emerald Sleet Targets Policy Research Organizations

https://www.microsoft.com/en-us/security/blog/2023/12/13/emerald-sleet-targets-policy-research-organizations/

Kimsuky APT Group Deploys New Social Engineering Campaign

https://www.ahnlab.com/en/asec-report-kimsuky-apt-group/

North Korean APT Kimsuky Deploying New Reconnaissance Tools

https://www.volexity.com/blog/2021/08/24/north-korean-bluelight-special-apt37-deploys-rokrat/

North Korean Kimsuky APT continues to target South Korea

https://www.welivesecurity.com/2023/11/23/north-korean-kimsuky-apt-continues-target-south-korea/

Tracking Kimsuky's Random Query Credential Stealer

https://www.volexity.com/blog/2021/08/24/north-korean-bluestorm-targeting-of-cryptocurrency-businesses/

Securonix: STIFF#BIZON - Kimsuky's Social Engineering Campaign

https://www.securonix.com/blog/stiffbizon-analyzing-kimsukys-social-engineering-campaign/

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.malwarebytes.com/blog/threat-intelligence/2023/02/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor

North Korean Kimsuky APT Launches Targeted Cyber Attacks on Energy and Defense Sectors

https://asec.ahnlab.com/en/56972/

APT43: North Korean Group Targeting US Think Tanks

https://www.mandiant.com/resources/blog/apt43-north-korean-group-exploits-weaknesses

Konni APT Organization Tracking

https://www.fortinet.com/blog/threat-research/konni-apt-organization-tracking

Kimsuky's Ongoing Campaign Targeting Think Tanks

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=35876

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://securelist.com/kimsukys-goldbackdoor/108141/

Microsoft: THALLIUM targets government employees with sophisticated spear-phishing campaigns

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-security-intelligence-report-highlights/

AhnLab: Kimsuky Group's APT Campaign Deploying AppleSeed

https://asec.ahnlab.com/en/52332/

North Korean APT Kimsuky Targeting Academic Institutions

https://www.mandiant.com/resources/blog/apt43-north-korean-group-intelligence-gathering

North Korean APT Kimsuky Targeting Universities

https://www.sentinelone.com/labs/kimsuky-north-korean-apt-targeting-universities/

Kimsuky Group: Tracking the King of Spear Phishing

https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/operation-earth-kitsune-tracking-kimsuky-apt-group

Kimsuky APT continues to target South Korean government using AppleSeed backdoor

https://www.mandiant.com/resources/blog/kimsuky-appleseeed-backdoor

AhnLab: Kimsuky Group's APT Campaign Using Multi-Stage Infection Process

https://asec.ahnlab.com/en/49819/

Microsoft: THALLIUM continues to target think tanks with new tactics

https://www.microsoft.com/en-us/security/blog/2019/12/30/microsoft-security-intelligence-report-thallium-north-korean-threat-actor/

CISA Alert: AppleJeus - Analysis of North Korea's Cryptocurrency Malware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a

AhnLab: Kimsuky Group's APT Campaign Targeting Korean Language Users

https://asec.ahnlab.com/en/62176/

JPCERT: Kimsuky Group Attack Techniques and Infrastructure

https://blogs.jpcert.or.jp/en/2024/02/kimsuky-attack.html

ASEC: Kimsuky Group's APT Attack Using Chrome Remote Desktop

https://asec.ahnlab.com/en/49712/

AhnLab: Analysis of Kimsuky Group's APT Attacks Exploiting Personal Information

https://asec.ahnlab.com/en/category/malware-information/apt/

KISA: Kimsuky Group APT Campaign Analysis

https://www.boho.or.kr/en/

Kaspersky: Kimsuky's GoldDragon Cluster and Its Backdoor

https://securelist.com/kimsukys-golddragon-cluster/109225/

Kimsuky's GoldDragon cluster and its C2 operations

https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/108756/

Kimsuky's GoldDragon cluster and its C2 operations

https://www.sentinelone.com/labs/kimsuky-golddragon-cluster-c2-operations/

STOLEN PENCIL Campaign Targets Academia

https://www.netskope.com/blog/stolen-pencil-campaign-targets-academia

Kimsuky's Multi-Stage Infection Chain Targeting South Korean Entities

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=32857

Kimsuky targeting South Korean academia with new reconnaissance malware

https://securelist.com/kimsuky-targeting-south-korean-academia/111287/

DPRK Kimsuky APT Deploying Random Query Malicious Extension

https://www.mandiant.com/resources/blog/dprk-kimsuky-random-query

Kimsuky's GoldDragon cluster and its C2 operations

https://www.securonix.com/blog/kimsuky-golddragon-cluster-and-c2-operations/

Kimsuky group: tracking the king of spear phishing

https://securelist.com/kimsukys-golddragon-cluster/108711/

KIMSUKY's GoldDragon cluster and its C2 operations

https://blog.alyac.co.kr/4926

North Korean Kimsuky APT Exploits DMARC Policy Gaps for Credential Theft

https://www.proofpoint.com/us/blog/threat-insight/north-korean-kimsuky-apt-exploits-dmarc-policy-gaps-credential-theft

Kimsuky Using TRANSLATEXT Chrome Extension to Steal Sensitive Data

https://asec.ahnlab.com/en/58155/

Kimsuky Group's Phishing Attack Using Mailing Service of Domestic Company

https://asec.ahnlab.com/en/59133/