{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "kimsuky",
    "slug": "kimsuky",
    "name": "Kimsuky",
    "shortName": "Kimsuky",
    "country": "North Korea",
    "countryCode": "KP",
    "sponsorship": "state-sponsored",
    "status": "active",
    "activeSince": "2012",
    "prominence": 84,
    "mitreGroupId": "G0094",
    "malpediaSlug": "kimsuky",
    "tagline": "DPRK's policy-intelligence collectors. Impersonate journalists and academics to reach the small community of people who shape North Korea policy.",
    "bio": "Kimsuky exists to answer a narrow set of intelligence questions: what are foreign governments planning with respect to North Korea, what do sanctions enforcers know, and what are nuclear policy specialists concluding?\n\nIts target set is correspondingly small and specific — North Korea analysts at think tanks, academics studying the peninsula, journalists covering DPRK affairs, government officials working Korea policy, and sanctions-enforcement personnel. This is a community of perhaps a few thousand people worldwide, and Kimsuky has been working it for over a decade.\n\nThe tradecraft is social rather than technical. Operators impersonate journalists requesting interviews, conference organisers issuing invitations, and academics seeking peer review — approaches that are entirely routine for the targets and difficult to refuse. A May 2023 joint advisory from the U.S. and South Korea highlighted the group's practice of conducting extended benign correspondence, sometimes over many weeks, before any malicious content appears. Where a payload isn't needed, the group simply asks: several documented operations obtained sensitive policy assessments through nothing more than a plausible interview request.\n\nTechnically, the group favours malicious Office macros, browser extensions that quietly exfiltrate webmail, and — increasingly — abuse of legitimate cloud services for command and control. It has also targeted South Korean nuclear research institutes and, in 2014, the Korea Hydro & Nuclear Power company.",
    "attribution": {
      "sponsor": "North Korea",
      "service": "RGB — Reconnaissance General Bureau",
      "unit": "Assessed within the RGB structure",
      "confidence": "high",
      "summary": "Attributed to North Korea's Reconnaissance General Bureau in joint advisories from CISA, FBI, NSA, and the Republic of Korea's National Intelligence Service. The U.S. Treasury sanctioned Kimsuky in November 2023, describing it as subordinate to the RGB and stating that it gathers intelligence to support DPRK strategic objectives. South Korean authorities have separately sanctioned the group.",
      "sources": [
        {
          "org": "CISA / FBI / NSA / ROK NIS",
          "title": "North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media (AA23-derived joint advisory)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129b",
          "date": "2023-05-09"
        },
        {
          "org": "U.S. Department of the Treasury",
          "title": "Treasury Sanctions North Korean Kimsuky and Officials Supporting DPRK Weapons Programs",
          "url": "https://home.treasury.gov/news/press-releases/jy1935",
          "date": "2023-11-30"
        },
        {
          "org": "CISA / FBI",
          "title": "North Korean Advanced Persistent Threat Focus: Kimsuky (AA20-301A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a",
          "date": "2020-10-27"
        }
      ]
    },
    "motivations": [
      "espionage"
    ],
    "targetSectors": [
      "Think Tanks & Academia",
      "Government",
      "Media & Journalism",
      "Defense",
      "Nuclear",
      "Education",
      "NGO & Civil Society",
      "Energy"
    ],
    "targetCountries": [
      "South Korea",
      "United States",
      "Japan",
      "Germany",
      "United Kingdom",
      "Russia",
      "China"
    ],
    "aliases": [
      {
        "org": "mitre",
        "name": "Kimsuky",
        "url": "https://attack.mitre.org/groups/G0094/",
        "correlation": "exact"
      },
      {
        "org": "microsoft",
        "name": "Emerald Sleet",
        "correlation": "exact",
        "note": "Formerly THALLIUM"
      },
      {
        "org": "microsoft",
        "name": "THALLIUM",
        "correlation": "exact",
        "note": "Retired designator"
      },
      {
        "org": "crowdstrike",
        "name": "Velvet Chollima",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "APT43",
        "correlation": "exact",
        "note": "Mandiant graduated the cluster to APT43 in March 2023"
      },
      {
        "org": "secureworks",
        "name": "NICKEL KIMBALL",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Sparkling Pisces",
        "correlation": "exact"
      },
      {
        "org": "proofpoint",
        "name": "TA427",
        "correlation": "exact"
      },
      {
        "org": "kaspersky",
        "name": "Kimsuky",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "Kimsuky / HIDDEN COBRA",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "TAG-71",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "BabyShark",
        "type": "backdoor",
        "custom": true,
        "description": "VBScript and HTA-based backdoor delivered through malicious Office documents.",
        "malpediaSlug": "vbs.babyshark"
      },
      {
        "name": "AppleSeed",
        "type": "backdoor",
        "custom": true,
        "description": "Windows backdoor supporting keylogging, screenshots, and USB monitoring, with a companion Android variant.",
        "malpediaSlug": "win.appleseed"
      },
      {
        "name": "SHARPEXT",
        "type": "malware",
        "custom": true,
        "description": "Malicious browser extension that reads Gmail and AOL mail directly from an authenticated session — invisible to login alerts and MFA."
      },
      {
        "name": "ReconShark",
        "type": "malware",
        "custom": true,
        "description": "Reconnaissance implant that profiles the host and installed security products before further stages are delivered."
      },
      {
        "name": "Fake interview requests",
        "type": "utility",
        "custom": false,
        "description": "Journalist and academic personas obtaining policy assessments through correspondence alone, with no malware involved."
      },
      {
        "name": "Chrome remote debugging",
        "type": "lotl",
        "custom": false,
        "description": "Abuse of the browser's own debugging interface to read authenticated sessions without credential theft."
      }
    ],
    "techniques": [
      {
        "tCode": "T1585.002",
        "name": "Establish Accounts: Email Accounts",
        "tactic": "Resource Development",
        "note": "Personas impersonating journalists, academics, and conference organisers"
      },
      {
        "tCode": "T1598.003",
        "name": "Phishing for Information: Spearphishing Link",
        "tactic": "Reconnaissance",
        "note": "Extended benign correspondence, sometimes over weeks, before any payload"
      },
      {
        "tCode": "T1566.001",
        "name": "Phishing: Spearphishing Attachment",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1176",
        "name": "Software Extensions",
        "tactic": "Persistence",
        "note": "SHARPEXT browser extension reading mail from an authenticated session"
      },
      {
        "tCode": "T1114.003",
        "name": "Email Collection: Email Forwarding Rule",
        "tactic": "Collection",
        "note": "Persistent forwarding rules surviving password resets"
      },
      {
        "tCode": "T1059.005",
        "name": "Command and Scripting Interpreter: Visual Basic",
        "tactic": "Execution"
      },
      {
        "tCode": "T1547.001",
        "name": "Boot or Logon Autostart Execution: Registry Run Keys",
        "tactic": "Persistence"
      },
      {
        "tCode": "T1056.001",
        "name": "Input Capture: Keylogging",
        "tactic": "Collection"
      },
      {
        "tCode": "T1102",
        "name": "Web Service",
        "tactic": "Command and Control",
        "note": "Legitimate cloud and blog services used as C2 channels"
      },
      {
        "tCode": "T1585.001",
        "name": "Establish Accounts: Social Media Accounts",
        "tactic": "Resource Development"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2017-11882",
        "firstExploited": "2018-06-01",
        "usage": "Equation Editor overflow embedded in policy-themed lure documents sent to Korea analysts.",
        "source": {
          "org": "CISA / FBI",
          "title": "North Korean APT Focus: Kimsuky (AA20-301A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a",
          "date": "2020-10-27"
        }
      },
      {
        "cveId": "CVE-2022-30190",
        "firstExploited": "2022-06-01",
        "usage": "Follina MSDT exploit used to execute payloads from documents without macros.",
        "source": {
          "org": "AhnLab ASEC",
          "title": "Kimsuky group exploiting CVE-2022-30190",
          "url": "https://asec.ahnlab.com/en/",
          "date": "2022-06-15"
        }
      },
      {
        "cveId": "CVE-2023-42793",
        "firstExploited": "2023-10-01",
        "usage": "TeamCity RCE exploited alongside other DPRK actors for access to software build environments.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Multiple North Korean threat actors exploiting the TeamCity CVE-2023-42793 vulnerability",
          "url": "https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/",
          "date": "2023-10-18"
        }
      },
      {
        "cveId": "CVE-2023-38831",
        "firstExploited": "2023-10-01",
        "usage": "WinRAR spoofing vulnerability used to deliver payloads in archives sent to policy targets.",
        "source": {
          "org": "Google Threat Analysis Group",
          "title": "Government-backed actors exploiting WinRAR vulnerability",
          "url": "https://blog.google/threat-analysis-group/government-backed-actors-exploiting-winrar-vulnerability/",
          "date": "2023-10-18"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "lazarus",
        "type": "same-sponsor",
        "confidence": "high",
        "note": "Both RGB, with divergent missions — Kimsuky collects policy intelligence, Lazarus generates revenue."
      },
      {
        "relatedActorId": "apt37",
        "type": "same-sponsor",
        "confidence": "high",
        "note": "Overlapping target sets in South Korean policy and defector communities, with distinct toolsets."
      },
      {
        "relatedActorId": "andariel",
        "type": "same-sponsor",
        "confidence": "moderate",
        "note": "Both DPRK state actors under the RGB umbrella."
      }
    ],
    "reports": [
      {
        "org": "CISA / FBI / NSA / ROK NIS",
        "title": "AA23-129B: North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129b",
        "date": "2023-05-09"
      },
      {
        "org": "Mandiant",
        "title": "APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations",
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/apt43-north-korea-cybercrime-espionage",
        "date": "2023-03-28"
      },
      {
        "org": "Volexity",
        "title": "SharpTongue Deploys Clever Mail-Stealing Browser Extension SHARPEXT",
        "url": "https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/",
        "date": "2022-07-28"
      }
    ],
    "campaigns": [],
    "flag": "🇰🇵",
    "profile": "/apt/kimsuky/"
  }
}