Cyber threat actor
Kimsuky
North Korean state-sponsored (Reconnaissance General Bureau) · active since 2012
Intelligence-collection group focused on Korean Peninsula policy experts and US think tanks, using elaborate spearphishing and credential-harvesting personas.
Aliases
Velvet ChollimaEmerald SleetAPT43
Primary targets
Think tanks Korean Peninsula policy experts Government officials Journalists
MITRE ATT&CK techniques
0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
No MITRE ATT&CK mapping available yet for Kimsuky.
Curated incidents
- 2020-10-28·Government / Think Tanks·United States, South KoreaCISA warns Kimsuky targeting US think tanks on Korean Peninsula policy
Joint advisory describes global intelligence-gathering campaign against experts and organizations focused on North Korea policy.