Kimsuky

G0094

Threat group.View on attack.mitre.org

About this group

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.

Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.

DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

Techniques used130

Procedure examples130

TechniqueProcedure example
T1003.001
LSASS Memory

Kimsuky has gathered credentials using Mimikatz and ProcDump.

T1005
Data from Local System

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1007
System Service Discovery

Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.

T1012
Query Registry

Kimsuky has obtained specific Registry keys and values on a compromised host.

T1016
System Network Configuration Discovery

Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`.

T1020
Automated Exfiltration

Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.

T1021.001
Remote Desktop Protocol

Kimsuky has used RDP for direct remote point-and-click access.

T1027
Obfuscated Files or Information

Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis.

T1027.001
Binary Padding

Kimsuky has performed padding of PowerShell command line code with over 100 spaces.

T1027.002
Software Packing

Kimsuky has packed malware with UPX.

T1027.007
Dynamic API Resolution

Kimsuky has leveraged dynamic API resolution using custom hashing techniques.

T1027.010
Command Obfuscation

Kimsuky has encoded malicious PowerShell scripts using Base64.

T1027.012
LNK Icon Smuggling

Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script.

T1027.013
Encrypted/Encoded File

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads.

T1027.015
Compression

Kimsuky has delivered malicious payloads within Zip archives.

View all 130 procedure examples

Software19

Campaigns0

None recorded.

References10

  1. AhnLab Kimsuky Kabar Cobra Feb 2019 Open source
    AhnLab. (2019, February 28). Operation Kabar Cobra - Tenacious cyber-espionage campaign by Kimsuky Group. Retrieved September 29, 2021.
  2. CISA AA20-301A Kimsuky Open source
    CISA, FBI, CNMF. (2020, October 27). https://us-cert.cisa.gov/ncas/alerts/aa20-301a. Retrieved November 4, 2020.
  3. Cybereason Kimsuky November 2020 Open source
    Dahan, A. et al. (2020, November 2). Back to the Future: Inside the Kimsuky KGH Spyware Suite. Retrieved November 6, 2020.
  4. EST Kimsuky April 2019 Open source
    Alyac. (2019, April 3). Kimsuky Organization Steals Operation Stealth Power. Retrieved August 13, 2019.
  5. EST Kimsuky SmokeScreen April 2019 Open source
    ESTSecurity. (2019, April 17). Analysis of the APT Campaign ‘Smoke Screen’ targeting to Korea and US 출처: https://blog.alyac.co.kr/2243 [이스트시큐리티 알약 블로그]. Retrieved September 29, 2021.
  6. MSFT-AI Open source
    Microsoft Threat Intelligence. (2024, February 14). Staying ahead of threat actors in the age of AI. Retrieved March 11, 2024.
  7. Malwarebytes Kimsuky June 2021 Open source
    Jazi, H. (2021, June 1). Kimsuky APT continues to target South Korean government using AppleSeed backdoor. Retrieved June 10, 2021.
  8. Mandiant APT43 March 2024 Open source
    Mandiant. (2024, March 14). APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations. Retrieved May 3, 2024.
  9. Netscout Stolen Pencil Dec 2018 Open source
    ASERT team. (2018, December 5). STOLEN PENCIL Campaign Targets Academia. Retrieved February 5, 2019.
  10. Proofpoint TA427 April 2024 Open source
    Lesnewich, G. et al. (2024, April 16). From Social Engineering to DMARC Abuse: TA427’s Art of Information Gathering. Retrieved May 3, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.