G0094 · 93 ATT&CK techniques · 1 correlated reports

Kimsuky

Aliases: Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427

Kimsuky is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially focused on targeting South Korean government entities, think tanks, and individuals identified as experts in various fields, and expanded its operations to include the UN and the government, education, business services, and manufacturing sectors in the United States, Japan, Russia, and Europe. Kimsuky has focused its intelligence collection activities on foreign policy and national security issues related to the Korean peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean cyber espionage actors likely as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

Open interactive actor investigation

ATT&CK techniques

T1005
Data from Local System
T1587.001
Malware
T1583
Acquire Infrastructure
T1021.001
Remote Desktop Protocol
T1585.002
Email Accounts
T1204.002
Malicious File
T1040
Network Sniffing
T1566.002
Spearphishing Link
T1588.002
Tool
T1078.003
Local Accounts
T1140
Deobfuscate/Decode Files or Information
T1608.001
Upload Malware
T1105
Ingress Tool Transfer
T1587
Develop Capabilities
T1567.002
Exfiltration to Cloud Storage
T1598
Phishing for Information
T1553.002
Code Signing
T1036.004
Masquerade Task or Service
T1102.002
Bidirectional Communication
T1204.001
Malicious Link
T1534
Internal Spearphishing
T1190
Exploit Public-Facing Application
T1593.001
Social Media
T1589.003
Employee Names
T1218.011
Rundll32
T1564.002
Hidden Users
T1176
Browser Extensions
T1070.004
File Deletion
T1219
Remote Access Software
T1583.004
Server
T1620
Reflective Code Loading
T1111
Multi-Factor Authentication Interception
T1594
Search Victim-Owned Websites
T1059.003
Windows Command Shell
T1583.001
Domains
T1012
Query Registry
T1591
Gather Victim Org Information
T1071.001
Web Protocols
T1585.001
Social Media Accounts
T1657
Financial Theft
T1136.001
Local Account
T1007
System Service Discovery
T1586.002
Email Accounts
T1560.003
Archive via Custom Method
T1070.006
Timestomp
T1598.003
Spearphishing Link
T1550.002
Pass the Hash
T1557
Adversary-in-the-Middle
T1518.001
Security Software Discovery
T1218.005
Mshta
T1041
Exfiltration Over C2 Channel
T1133
External Remote Services
T1082
System Information Discovery
T1584.001
Domains
T1589.002
Email Addresses
T1059.007
JavaScript
T1027
Obfuscated Files or Information
T1074.001
Local Data Staging
T1071.003
Mail Protocols
T1056.001
Keylogging
T1027.002
Software Packing
T1552.001
Credentials In Files
T1560.001
Archive via Utility
T1016
System Network Configuration Discovery
T1555.003
Credentials from Web Browsers
T1546.001
Change Default File Association
T1566.001
Spearphishing Attachment
T1057
Process Discovery
T1055
Process Injection
T1112
Modify Registry
T1059.001
PowerShell
T1562.004
Disable or Modify System Firewall
T1588.005
Exploits
T1218.010
Regsvr32
T1547.001
Registry Run Keys / Startup Folder
T1562.001
Disable or Modify Tools
T1543.003
Windows Service
T1583.006
Web Services
T1083
File and Directory Discovery
T1564.003
Hidden Window
T1053.005
Scheduled Task
T1036.005
Match Legitimate Name or Location
T1593.002
Search Engines
T1055.012
Process Hollowing
T1114.003
Email Forwarding Rule
T1071.002
File Transfer Protocols
T1003.001
LSASS Memory
T1059.005
Visual Basic
T1098.007
Additional Local or Domain Groups
T1059.006
Python
T1505.003
Web Shell
T1114.002
Remote Email Collection
T1036
Masquerading

Correlated CTI and IR reports

Continue the investigation