Skip to content
North KoreaState-SponsoredActiveMITRE G0094Malpedia ↗

Kimsuky

DPRK's policy-intelligence collectors. Impersonate journalists and academics to reach the small community of people who shape North Korea policy.

ATTRIBUTED TONorth Korea › RGB — Reconnaissance General Bureau › Assessed within the RGB structure

Open MITRE Navigator layer ↗Download profile JSON
Active
2012–present
Motivation
Espionage
Aliases
11
Exploited CVEs
4
ATT&CK techniques
10
Cited sources
10

Overview

Kimsuky exists to answer a narrow set of intelligence questions: what are foreign governments planning with respect to North Korea, what do sanctions enforcers know, and what are nuclear policy specialists concluding?

Its target set is correspondingly small and specific — North Korea analysts at think tanks, academics studying the peninsula, journalists covering DPRK affairs, government officials working Korea policy, and sanctions-enforcement personnel. This is a community of perhaps a few thousand people worldwide, and Kimsuky has been working it for over a decade.

The tradecraft is social rather than technical. Operators impersonate journalists requesting interviews, conference organisers issuing invitations, and academics seeking peer review — approaches that are entirely routine for the targets and difficult to refuse. A May 2023 joint advisory from the U.S. and South Korea highlighted the group's practice of conducting extended benign correspondence, sometimes over many weeks, before any malicious content appears. Where a payload isn't needed, the group simply asks: several documented operations obtained sensitive policy assessments through nothing more than a plausible interview request.

Technically, the group favours malicious Office macros, browser extensions that quietly exfiltrate webmail, and — increasingly — abuse of legitimate cloud services for command and control. It has also targeted South Korean nuclear research institutes and, in 2014, the Korea Hydro & Nuclear Power company.

Attribution

Down to the named unit where public evidence supports it.

North KoreaRGB — Reconnaissance General BureauAssessed within the RGB structureHigh confidence

Attributed to North Korea's Reconnaissance General Bureau in joint advisories from CISA, FBI, NSA, and the Republic of Korea's National Intelligence Service. The U.S. Treasury sanctioned Kimsuky in November 2023, describing it as subordinate to the RGB and stating that it gathers intelligence to support DPRK strategic objectives. South Korean authorities have separately sanctioned the group.

Attributing sources

Cross-vendor naming crosswalk

11 designators across 10 organisations.

MITRE ATT&CK

index ↗
  • Kimsuky

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Emerald SleetFormerly THALLIUM
  • THALLIUMRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Velvet Chollima

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT43Mandiant graduated the cluster to APT43 in March 2023

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • NICKEL KIMBALL

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Sparkling Pisces

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • TAG-71

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Kaspersky GReAT

index ↗
  • Kimsuky

Descriptive names, often coined from a distinctive string or artifact in the toolset.

Proofpoint

index ↗
  • TA427

TA### ('Threat Actor'), numbered sequentially in order of first tracking.

CISA / NSA / FBI

index ↗
  • Kimsuky / HIDDEN COBRA

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

South KoreaUnited StatesJapanGermanyUnited KingdomRussiaChina

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

BabySharkbackdoor

VBScript and HTA-based backdoor delivered through malicious Office documents.

Malpedia ↗
AppleSeedbackdoor

Windows backdoor supporting keylogging, screenshots, and USB monitoring, with a companion Android variant.

Malpedia ↗
SHARPEXTmalware

Malicious browser extension that reads Gmail and AOL mail directly from an authenticated session — invisible to login alerts and MFA.

ReconSharkmalware

Reconnaissance implant that profiles the host and installed security products before further stages are delivered.

Shared, commodity & living-off-the-land

Fake interview requestsutility

Journalist and academic personas obtaining policy assessments through correspondence alone, with no malware involved.

Chrome remote debugginglotl

Abuse of the browser's own debugging interface to read authenticated sessions without credential theft.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by Kimsuky
CVE-2023-42793KEVransomware9.81 Oct 2023TeamCity RCE exploited alongside other DPRK actors for access to software build environments.SRCMicrosoft Threat Intelligence
CVE-2023-38831KEVransomware7.81 Oct 2023WinRAR spoofing vulnerability used to deliver payloads in archives sent to policy targets.SRCGoogle Threat Analysis Group
CVE-2022-30190KEVransomware7.81 Jun 2022Follina MSDT exploit used to execute payloads from documents without macros.SRCAhnLab ASEC
CVE-2017-11882KEVransomware7.81 Jun 2018Equation Editor overflow embedded in policy-themed lure documents sent to Korea analysts.SRCCISA / FBI

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 10 techniques
  1. 07

    Command and Control

    1 technique·derived

    Legitimate cloud and blog services used as C2 channels.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 7 tactics · 5 with actor-specific notes

Reconnaissance

1

Resource Development

2

Persistence

2

Collection

2

Command and Control

1

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.