Kimsuky

APT / EstatalG0094 ↗
Origen🇰🇵 Coreia do Norte
Técnicas (MITRE ATT&CK)130
FuenteMITRE ATT&CK
Patrocinio estatal: Korea (Democratic People's Republic of)Confianza de atribución: 50%Categorías objetivo: Government, Private sector
Regiones atacadas: Ministry of Unification · Sejong Institute · Korea Institute for Defense Analyses · Germany
También conocido como:APT43Black BansheeEarth KumihoEmerald SleetG0086Operation Stolen PencilPatheticSlugSparkling PiscesSpringtailTA427THALLIUMThalliumVelvet Chollima

Sobre el grupo

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overl

Cadena de ataque

Escenario plausible montado a partir de las técnicas reales del grupo, ordenadas por las fases de un ataque. Cada etapa muestra cómo suele actuar el grupo.

Severidad del arsenal86
Impacto: Alto
T1190T1053.005T1098.007T1546.001T1005T1020ENTRYAcceso inicialExploitPublic-Facing App…EXECEjecuciónScheduled TaskPERSPersistenciaAdditional Localor Domain GroupsPRIVEscalada de privilegiosChange DefaultFile AssociationCOLLRecolecciónData from LocalSystemEXFILExfiltraciónAutomatedExfiltrationIMPACTImpactoService Stop

Cadena ilustrativa derivada de las técnicas documentadas en MITRE ATT&CK — no representa un ataque específico ya ocurrido. La severidad resume el arsenal conocido (cobertura de la cadena, CVEs en explotación activa, técnicas).

Técnicas (MITRE ATT&CK) 130

Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.

Escalada de privilegios

Vulnerabilidades explotadas 3

CVEs que este grupo es conocido por explotar, según MITRE ATT&CK. Ordenadas por gravedad real.

Infraestructura conocida 69

Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha256_hashdce69e096e6b7a54db14431f5208870070503e1961e3f9912c6bbc42fd43ac55Amadeythreatfox
sha256_hash427beb78a7bf619fe38d09ef036c4d0c12eb92cf5765db8d216242ddc3df6538Amadeythreatfox
sha256_hash6E7BC331F4783AD99D83D127FBD2B9540AB34A51242FDC7305343F086BE65746Amadeythreatfox
sha256_hashF8770351861C949E2D528B2DB8FFB0331B0F54F82CC321DBF3EA6C59A6D6BA31Amadeythreatfox
ip:port193.178.158.107:80Amadeythreatfox
urlhttp://193.178.158.107/Bjsw3DlG1/index.phpAmadeythreatfox
urlhttp://194.102.105.70/8jdjZhdf7/Login.phpAmadeythreatfox
md5_hash5a52ab26c92887b367383c8c47d1f825Amadeythreatfox
sha1_hash6ac13b1d254972f48fab7a854cec277261c3538eAmadeythreatfox
sha256_hash52ebd649910eac2754dd5631d388dfdcf25e200be19918d1c94999225729a73cAmadeythreatfox
md5_hash6f2da55a79f65a87ad3d36492e7fb9f0Amadeythreatfox
sha256_hashbb04d6d6fccd0c5eaaeb02bc0c904c0122e9a61d0756b579c2d0da760190b576Amadeythreatfox
sha1_hashf425d0cdc51db0f3e0bcb70ea600767655c67fb2Amadeythreatfox
urlhttp://194.102.105.70/8jdjZhdf7/index.phpAmadeythreatfox
urlhttp://194.102.105.70/8jdjZhdf7/Plugins/cred.dllAmadeyurlhaus
urlhttp://194.102.105.70/8jdjZhdf7/Plugins/cred64.dllAmadeyurlhaus
sha256_hash3f050137b9f180dc883989c7717227cedfeb4c72ebfeca415578b8c5a875fa6aAmadeythreatfox
sha256_hasha0aba2cd26e36e75b4a1c49aa63438b5cc442ee164e0edb94cd35444ee999b2dAmadeythreatfox
md5_hashd022bb6de095252f2b2051fe822c3fbeAmadeythreatfox
sha1_hash447ca548a1d7d6cbb50eafe0d0edc1580cf55c41Amadeythreatfox
sha256_hash2b20eb4237ad2eab05c4a2ad261bcfd436663cf32e2a45526e17dfd3a51a095dAmadeythreatfox
md5_hashc5616af2cef3dcdb095d8cc55db75c96Amadeythreatfox
sha1_hash3c584320e4f7523645ed71d09321d2f5a476f103Amadeythreatfox
sha256_hash76e6367d8123171afa540fe92a3758424ec7d1e029c4e5a3b9771e24fe0085c1Amadeythreatfox
md5_hash9b93fde0cd1f8252a2abf2239ae56f9dAmadeythreatfox
sha1_hashc5f12a9d191c2baf64d66eb1f2edd6754333260dAmadeythreatfox
sha256_hash0ebd28830251fc40845f4201396c683b0026828f3dc25873abdb6feac66820adAmadeythreatfox
urlhttp://cloudscrsolutions.com/v8sjh3hs8/index.phpAmadeythreatfox
urlhttp://atraflaxtt.com/g9sjh3djv/index.phpAmadeythreatfox
urlhttp://jazoopsloo.info/k92lsA3dpb/index.phpAmadeythreatfox

+69 indicadores en total. Míralos todos en la página de IOCs.

El grupo Kimsuky usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →