Threat actor · all actors
KAERI VPN intrusion (South Korea, 2021)INS-KAERI-2021 insider
🇰🇷 KR
aka KAERI hack 2021
Last updated:
0attributed CVEs
0ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
Korea Atomic Energy Research Institute disclosed June 2021 that 13 unauthorised accesses had occurred via a VPN vulnerability; South Korean parliament members and AhnLab attributed the activity to DPRK-aligned Kimsuky. No domestic insider charged; investigation focused on credential misuse.
How we know this
- Data origin
- Curated overlay Insider-threat entry synthesised from public reporting and court filings — not a MITRE-tracked intrusion set.
- Techniques
- No ATT&CK techniques mapped.
- Named victims
- 1 extracted from reporting.
Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty. Only one named victim is on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
No techniques attributed.
Co-occurring actors
None.