Active since: 2012
Targeted Regions: South Korea, United States, Japan, Vietnam, Thailand, Brazil, Germany, Russia, Canada, and broader Europe, including Belgium, Bulgaria, Croatia, Czech Republic, Denmark, Estonia, Finland, France, Greece, Hungary, Iceland, Italy, Latvia, Lithuania, Luxembourg, Montenegro, Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, and Albania. East Asia, Southeast Asia, Asia-Pacific, and North America are described as regional focus areas.
Targeted Platforms: Windows, Android, Linux, macOS, and cloud or web services and VPN portals
Targeted Products: GitHub, Pastebin, Dropbox, Slack, Cloudflare Quick Tunnels, Visual Studio, Microsoft 365, Okta
Targeted Industries: Government, Public Administration, Defense, Think Tanks, Policy Research Institutes, Academia, Universities, NGOs, Human Rights Organizations, Media, Healthcare, Machinery, Energy, Nuclear Power Operations, Manufacturing, Business Services, Legal Services, Construction, Financial, Insurance, Retail, Cryptocurrency
Threat Actor: Kimsuky (aka APT43, Thallium, Velvet Chollima, Black Banshee, Emerald Sleet, Ruby Sleet, Sparkling Pisces, Springtail, TA427, TA406, Earth Kumiho, PatheticSlug, ARCHIPELAGO, SharpTongue, ITG16, Greendinosa, RGB-D5, Cerium)
Malware: AppleSeed (KGH_SPY), AlphaSeed, HappyDoor, PebbleDash, HelloDoor, httpMalice, httpTroy, MemLoad, HTTPSpy, AsyncRAT, BabyShark, GoldDragon, KLogEXE, Troll Stealer, Gomir, NavRAT, NikiHTTP, NikiTeaR, ComeBacker, DRATzarus, FastFire, FastSpy, FlowerPower, RandomQuery, Yorekey, Grease, TRANSLATEXT, QuasarRAT, Gh0st RAT, KimJongRAT, CSPY Downloader, BITTERSWEET, VENOMBITE, xRAT, MailFetch.py, Reger Dropper, Pidoc Dropper
Campaign Names: Operation GitPower, quishing (QR code phishing) campaigns, and Operation Kabar Cobra
Timeline
| Date | Event |
|---|---|
| 2012 | Kimsuky active since at least 2012 |
| 2019 | Kimsuky attacks South Korea’s defense and media sectors; malware filed as “Cobra”, mutex “KABAR” |
| 2023 | Operation Kabar Cobra conducted |
| May 2025 | First recorded Kimsuky use of commercial LLMs |
| August 2026 | Operation GitPower conducted; multiple quishing campaigns target think tanks and U.S. entities |
Actor Details
CVE-2017-11882 and CVE-2019-0708, plus CVE-2018-0802, CVE-2019-1405, CVE-2020-0787, CVE-2024-1709, and CVE-2025-48703.Actor Group
| Name | Origin | Motive | Target Industries |
|---|---|---|---|
| Kimsuky (aka APT43, Thallium, Velvet Chollima, Black Banshee, Emerald Sleet, Ruby Sleet, Sparkling Pisces, Springtail, TA427, TA406, Earth Kumiho, PatheticSlug, ARCHIPELAGO, SharpTongue, ITG16, G0094) | North Korea (DPRK) | Espionage, Financial Gains | Government, Public Administration, Defense, Think Tanks, Policy Research Institutes, Academia, Universities, NGOs, Human Rights Organizations, Media, Healthcare, Machinery, Energy, Nuclear Power Operations, Manufacturing, Business Services, Legal Services, Construction, Financial, Insurance, Retail, Cryptocurrency |
Recommendations
Query for tasks named Edge Updater, ChromeUpdate, EdgeUpdate, ChromeCheck, and EdgeCheck, plus any task whose name pairs a real product name with a misspelling or a long numeric string, such as “BitLockor Encrypter All Drives”. Hidden tasks running PowerShell or regsvr32 at 5–60 minute intervals are the single most consistent persistence artifact.
Build detection for LNK files whose command-line argument field exceeds a few hundred characters or contains long runs of whitespace, and for LNK files delivered inside ZIP archives. Roughly 300 leading spaces and 5,800–9,500 character PowerShell arguments are the Operation GitPower fingerprint.
Flag conhost.exe launched with --headless, powershell.exe with -windowstyle hidden, and PowerShell child processes spawned by hh.exe, wscript.exe, or explorer.exe following archive extraction.
Watch for regsvr32.exe and rundll32.exe loading DLLs from C:\ProgramData, C:\Users\Public, and %TEMP%, and for certutil.exe performing decode operations against files under %USERPROFILE%\Links.
Treat Visual Studio Code Remote Tunnels, Cloudflare Quick Tunnels, and Ngrok as remote access software subject to allowlisting, and alert on the VS Code CLI executing from C:\Users\Public or on ‘code tunnel’ invocations on hosts with no development role.
Block or alert on DWAgent installation, the DWService service name, dwagsvc.exe, listener port 7950, and connections to dwservice.net relay nodes.
Alert on requests to raw.githubusercontent.com or api.github.com carrying an Authorization: token header from non-developer endpoints, on Pastebin raw path access, and on unexpected Dropbox API or Slack WebHook traffic from workstations.
Where South Korean government PKI certificates are used, move them off filesystem paths such as C:\GPKI onto hardware-backed storage, and audit access to that directory.
Potential MITRE ATT&CK TTPs
CVEs Previously Leveraged by Kimsuky
| CVE | Name | Affected Product |
|---|---|---|
CVE-2017-11882 | Microsoft Office Memory Corruption Vulnerability | Microsoft Office |
CVE-2018-0802 | Microsoft Office Memory Corruption Vulnerability | Microsoft Office, Microsoft Word |
CVE-2019-0708 | BlueKeep (Microsoft Remote Desktop Services RCE) | Windows, Windows Server |
CVE-2019-1405 | Microsoft Windows UPnP Service Privilege Escalation Vulnerability | Windows, Windows Server |
CVE-2020-0787 | Microsoft Windows BITS Improper Privilege Management Vulnerability | Microsoft Windows |
CVE-2024-1709 | ConnectWise ScreenConnect Authentication Bypass Vulnerability | ConnectWise ScreenConnect |
CVE-2025-48703 | CWP Control Web Panel OS Command Injection Vulnerability | CWP (aka Control Web Panel or CentOS Web Panel) |
Indicators of Compromise (IOCs)
| Type | Value |
|---|---|
| SHA256 (sample) | 1eff237dee95172363bfc0342d0389f809f753a6ec5e6848e57b3fd5482e9793,85f8f8a3f28d2956776fbbd0365cdb78ac8dc1e6ed12818ef18caed0bb2f74c8,af50f35701916d3909f2727cdcbde1a7af47f46eb8db3996905b1c0725aa133f,d7c09e7bf79aa9b786dcd9f870427f4a1110f702646fba9d3835215ad3649d0b,a36576a096db24a1c91327eb547dedf52e5bd4b0d4593b88d9593d377585b922,981dadc1a7ab50d6ff600a69c904a350fcc2d2050ac94589321f51ac5527c78d,18fa10ff013cf82974f00875e23dae48d4d2dc0993a348f8069dd32845de39a1,a4f72ce8b5736fe3ca2083cfe21bd51697f12e900e307c357cb8523b8f86e3ec,c62677543eeb50e0def44fc75009a7748cdbedd0a3ccf62f50d7f219f6a5aa05,e8000ddfddbe120b5f2fb3677abbad901615d1abd01a0de204fade5d2dd5ad0d,da79eea1198a1a10e2ffd50fd949521632d8f252fb1aadb57a45218482b9fd89… see original advisory for MD5/SHA1/full set |
| Domains (sample) | www[.]ibizplus[.]n-e[.]kr,load[.]serverpit[.]com,conference[.]birdriver[.]org,download[.]birdriver[.]org,hdrgdrfes[.]chickenkiller[.]com,pipeline[.]embeddedonline[.]org,appview[.]imagetemplate[.]com,bigfile[.]jaycloudlab[.]com,bigfile[.]crabdance[.]com,niscarea[.]com,www[.]yespp[.]co[.]kr,www[.]pyrotech[.]co[.]kr,newjo-imd[.]com,nid-log[.]com,nid-tax[.]dns[.]army,pay-tax[.]dns[.]navy,nid-htl[.]duckdns[.]org,node896147[.]dwservice[.]net,www[.]dwservice[.]net |
| Filenames (sample) | Security_20260811.lnk,Visa5499.lnk,fgkpxjbgthy.ps1,xnciuegwpo.pdf,Visa_5499.png,api_reference.chm,SecurityMaker.chm,Link.dat,Link.ini,Office_Config.xml,nos-setup.exe,fix-camera.jse,mTSTCv8.mdxm,spyLoader.dll,httpSpy.dll,MemLoader.dll,security_20260126.scr,xipbkmaw.exe,dwagsvc.exe,config.db |
| Mutex | Global\AlreadyRunning19122345 |
| Registry Key | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\MSEdgeUpdateInstaller |
| Scheduled Task | Edge Updater, ChromeUpdate, EdgeUpdate, BitLockor Encrypter All Drives_102974298364124_skillerty |
| User Agent | Chremo/87.0.4280.141, Edgo/87.0.664.75, HeadlessChrome/151.0.0.0 |
References
- genians.co.kr — AI agent OpenCode threat intelligence
- breakglass.tech — Kimsuky CHM NIDLOG C2 dump
- cyfirma.com — APT profile: Kimsuky
- zimperium.com — Kimsuky weaponized QR codes
- enki.co.kr — Kimsuky advanced attack techniques
- securelist.com — Kimsuky AppleSeed/PebbleDash campaigns
- fbi.gov — North Korean Kimsuky actors leverage malicious QR
- rapid7.com — The updated APT playbook: Kimsuky
- huntress.com — Kimsuky threat library
- cisa.gov — AA20-301A
- attack.mitre.org — G0094 Kimsuky
- fortiguard.fortinet.com — Kimsuky threat actor profile
- hivepro.com — Kimsuky’s stealthy RDP espionage campaign
What Next?
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.
