About the group
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overl
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 130
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 3
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Known infrastructure 69
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
dce69e096e6b7a54db14431f5208870070503e1961e3f9912c6bbc42fd43ac55Amadeythreatfox427beb78a7bf619fe38d09ef036c4d0c12eb92cf5765db8d216242ddc3df6538Amadeythreatfox6E7BC331F4783AD99D83D127FBD2B9540AB34A51242FDC7305343F086BE65746AmadeythreatfoxF8770351861C949E2D528B2DB8FFB0331B0F54F82CC321DBF3EA6C59A6D6BA31Amadeythreatfox193.178.158.107:80Amadeythreatfoxhttp://193.178.158.107/Bjsw3DlG1/index.phpAmadeythreatfoxhttp://194.102.105.70/8jdjZhdf7/Login.phpAmadeythreatfox5a52ab26c92887b367383c8c47d1f825Amadeythreatfox6ac13b1d254972f48fab7a854cec277261c3538eAmadeythreatfox52ebd649910eac2754dd5631d388dfdcf25e200be19918d1c94999225729a73cAmadeythreatfox6f2da55a79f65a87ad3d36492e7fb9f0Amadeythreatfoxbb04d6d6fccd0c5eaaeb02bc0c904c0122e9a61d0756b579c2d0da760190b576Amadeythreatfoxf425d0cdc51db0f3e0bcb70ea600767655c67fb2Amadeythreatfoxhttp://194.102.105.70/8jdjZhdf7/index.phpAmadeythreatfoxhttp://194.102.105.70/8jdjZhdf7/Plugins/cred.dllAmadeyurlhaushttp://194.102.105.70/8jdjZhdf7/Plugins/cred64.dllAmadeyurlhaus3f050137b9f180dc883989c7717227cedfeb4c72ebfeca415578b8c5a875fa6aAmadeythreatfoxa0aba2cd26e36e75b4a1c49aa63438b5cc442ee164e0edb94cd35444ee999b2dAmadeythreatfoxd022bb6de095252f2b2051fe822c3fbeAmadeythreatfox447ca548a1d7d6cbb50eafe0d0edc1580cf55c41Amadeythreatfox2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095dAmadeythreatfoxc5616af2cef3dcdb095d8cc55db75c96Amadeythreatfox3c584320e4f7523645ed71d09321d2f5a476f103Amadeythreatfox76e6367d8123171afa540fe92a3758424ec7d1e029c4e5a3b9771e24fe0085c1Amadeythreatfox9b93fde0cd1f8252a2abf2239ae56f9dAmadeythreatfoxc5f12a9d191c2baf64d66eb1f2edd6754333260dAmadeythreatfox0ebd28830251fc40845f4201396c683b0026828f3dc25873abdb6feac66820adAmadeythreatfoxhttp://cloudscrsolutions.com/v8sjh3hs8/index.phpAmadeythreatfoxhttp://atraflaxtt.com/g9sjh3djv/index.phpAmadeythreatfoxhttp://jazoopsloo.info/k92lsA3dpb/index.phpAmadeythreatfox+69 indicators in total. See them all on the IOCs page.
References
Kimsuky uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →