Kimsuky has gathered credentials using Mimikatz and ProcDump.111213
group
Kimsuky G0094
- Created
- 26 August 2019
- Last modified
- 31 July 2026
- Aliases
- Kimsuky · Black Banshee · Velvet Chollima · Emerald Sleet · THALLIUM · APT43 · TA427 · Springtail · Earth Kumiho · PatheticSlug
Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.[1][2][3][4][5][6]
Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).[7][8][9] In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.[10]
DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0094
Kimsuky has collected Office, PDF, and HWP documents from its victims.1415 Kimsuky has also harvested victim files through the use of the RecentFiles() function that collects paths of recently accessed files by parsing .lnk shortcuts from %APPDATA%\Microsoft\Windows\Recent.16
Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.17
Kimsuky has obtained specific Registry keys and values on a compromised host.18
Kimsuky has used ipconfig/all and web beacons sent via email to gather network configuration information.1920 Kimsuky has also identified Host IP addresses leveraging the WMI class Win32_NetworkAdapterConfiguration.21
Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.22
Standing G0094
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
100th percentile · None of the 176 ATT&CK groups has more Enterprise techniques — the highest in the population.
100th percentile · None of the 176 ATT&CK groups has more tactics spanned — the highest in the population.
93rd percentile · 93% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
15th percentile · 85% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G0094
2589 distinct rules cover the 130 techniques recorded for this group. The 3109 technique-to-rule mappings resolve to 2589 distinct rules, because one rule can cover several techniques. 1713 Sigma · 876 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org