Threat group.View on attack.mitre.org
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.
Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.
DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Kimsuky has gathered credentials using Mimikatz and ProcDump. |
| T1005 Data from Local System |
Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`. |
| T1007 System Service Discovery |
Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system. |
| T1012 Query Registry |
Kimsuky has obtained specific Registry keys and values on a compromised host. |
| T1016 System Network Configuration Discovery |
Kimsuky has used `ipconfig/all` and web beacons sent via email to gather network configuration information. Kimsuky has also identified Host IP addresses leveraging the WMI class `Win32_NetworkAdapterConfiguration`. |
| T1020 Automated Exfiltration |
Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames. |
| T1021.001 Remote Desktop Protocol |
Kimsuky has used RDP for direct remote point-and-click access. |
| T1027 Obfuscated Files or Information |
Kimsuky has obfuscated binary strings including the use of XOR encryption and Base64 encoding. Kimsuky has also modified the first byte of DLL implants targeting victims to prevent recognition of the executable file format. Kimsuky has obfuscated strings using Single Instruction Multiple Data (SIMD) instructions that complicate static analysis. |
| T1027.001 Binary Padding |
Kimsuky has performed padding of PowerShell command line code with over 100 spaces. |
| T1027.002 Software Packing |
Kimsuky has packed malware with UPX. |
| T1027.007 Dynamic API Resolution |
Kimsuky has leveraged dynamic API resolution using custom hashing techniques. |
| T1027.010 Command Obfuscation |
Kimsuky has encoded malicious PowerShell scripts using Base64. |
| T1027.012 LNK Icon Smuggling |
Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script. |
| T1027.013 Encrypted/Encoded File |
Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads. |
| T1027.015 Compression |
Kimsuky has delivered malicious payloads within Zip archives. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.