Threat actor · all actors
KimsukyG0094 state
🇰🇵 KP · RGB
aka Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Operation Stolen Pencil, G0086, Sparkling Pisces
Last updated: 2026-08-22
About this actor
[Kimsuky](https://attack.mitre.org/groups/G0094) is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. [Kimsuky](https://attack.mitre.org/groups/G0094) has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. [Kimsuky](https://attack.mitre.org/groups/G0094) operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.(Citation: EST Kimsuky April 2019)(Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: CISA AA20-301A Kimsuky)(Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024) [Kimsuky](https://attack.mitre.org/groups/G0094) was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).(Citation: Netscout Stolen Pencil Dec 2018)(Citation: EST Kimsuky SmokeScreen April 2019)(Citation: AhnLab Kimsuky Kabar Cobra Feb 2019) In 2023, [Kimsuky](https://attack.mitre.org/groups/G0094) was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.(Citation: MSFT-AI) DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under [Lazarus Group](https://attack.mitre.org/groups/G0032), rather than
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Mandiant / genericAPT numbering
Palo Alto Unit 42constellation names
ProofpointTA threat-actor id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 171 ATT&CK techniques on file.
- Named victims
- 2 extracted from reporting · 1 from the curated floor.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
- 2025 — 2 CVE published, 1 KEV added
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2025-49706 KEV | 7.8 | 6.5 | 0.9988 | 2025-07-08 | see CVE |
CVE-2025-12562 | 6.0 | 7.5 | 0.0084 | 2025-12-11 | see CVE |
CVE-2026-22813 | 4.8 | 6.1 | 0.0093 | 2026-01-12 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1005Data from Local System ↗T1007System Service Discovery ↗T1012Query Registry ↗T1016System Network Configuration Discovery ↗T1020Automated Exfiltration ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.001Binary Padding ↗T1027.002Software Packing ↗T1027.007Dynamic API Resolution ↗T1027.010Command Obfuscation ↗T1027.012LNK Icon Smuggling ↗T1027.013Encrypted/Encoded File ↗T1027.015Compression ↗T1027.016Junk Code Insertion ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1036.005Match Legitimate Resource Name or Location ↗T1036.007Double File Extension ↗T1040Network Sniffing ↗T1041Exfiltration Over C2 Channel ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1055Process Injection ↗T1055.001Dynamic-link Library Injection ↗T1055.012Process Hollowing ↗T1056Input Capture ↗T1056.001Keylogging ↗T1056.003Web Portal Capture ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1059.006Python ↗T1059.007JavaScript ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1070.006Timestomp ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1071.002File Transfer Protocols ↗T1071.003Mail Protocols ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.003Local Accounts ↗T1082System Information Discovery ↗T1083File and Directory Discovery ↗T1098Account Manipulation ↗T1098.007Additional Local or Domain Groups ↗T1102Web Service ↗T1102.001Dead Drop Resolver ↗T1102.002Bidirectional Communication ↗T1105Ingress Tool Transfer ↗T1106Native API ↗T1111Multi-Factor Authentication Interception ↗T1112Modify Registry ↗T1113Screen Capture ↗T1114Email Collection ↗T1114.002Remote Email Collection ↗T1114.003Email Forwarding Rule ↗T1115Clipboard Data ↗T1124System Time Discovery ↗T1132Data Encoding ↗T1132.002Non-Standard Encoding ↗T1133External Remote Services ↗T1136Create Account ↗T1136.001Local Account ↗T1140Deobfuscate/Decode Files or Information ↗T1176Software Extensions ↗T1176.001Browser Extensions ↗T1185Browser Session Hijacking ↗T1190Exploit Public-Facing Application ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1204.004Malicious Copy and Paste ↗T1205Traffic Signaling ↗T1217Browser Information Discovery ↗T1218System Binary Proxy Execution ↗T1218.005Mshta ↗T1218.010Regsvr32 ↗T1218.011Rundll32 ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1480Execution Guardrails ↗T1480.002Mutual Exclusion ↗T1489Service Stop ↗T1497Virtualization/Sandbox Evasion ↗T1497.001System Checks ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1534Internal Spearphishing ↗T1539Steal Web Session Cookie ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1546Event Triggered Execution ↗T1546.001Change Default File Association ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1552Unsecured Credentials ↗T1552.001Credentials In Files ↗T1552.004Private Keys ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1557Adversary-in-the-Middle ↗T1559Inter-Process Communication ↗T1559.001Component Object Model ↗T1560Archive Collected Data ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 85 / 171 | 50% |
CM-6 | 74 / 171 | 43% |
CM-2 | 63 / 171 | 37% |
SI-3 | 59 / 171 | 34% |
AC-6 | 53 / 171 | 31% |
AC-3 | 52 / 171 | 30% |
CA-7 | 51 / 171 | 30% |
CM-7 | 48 / 171 | 28% |
SC-7 | 46 / 171 | 27% |
AC-2 | 45 / 171 | 26% |
AC-4 | 42 / 171 | 25% |
SI-7 | 41 / 171 | 24% |
IA-2 | 39 / 171 | 23% |
AC-5 | 34 / 171 | 20% |
CM-5 | 33 / 171 | 19% |
Co-occurring actors
- SharePoint ToolShell Exploitation 1 shared CVEs
- Volt Typhoon 1 shared CVEs
- Mustang Panda 1 shared CVEs
- MuddyWater 1 shared CVEs
- Gamaredon Group 1 shared CVEs
Similar actors
Similar TTPs
- Magic Hound 0.37
- Mustang Panda 0.37
- Lazarus Group 0.36
- APT32 0.36
- Gamaredon Group 0.34
Overlapping CVEs
- Gamaredon Group 0.33
- MuddyWater 0.25
- Mustang Panda 0.25
- Volt Typhoon 0.17
- SharePoint ToolShell Exploitation 0.11
Active in same years
- SharePoint ToolShell Exploitation 2.00
- Volt Typhoon 2.00
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
Same nation-state
- Operation Dream Job 1.00
- 3CX Supply Chain Attack 1.00
- Lazarus Group 1.00
- APT37 1.00
- APT38 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00