Cyber overview
Cyber threat actor

Kimsuky

North Korean state-sponsored (Reconnaissance General Bureau) · active since 2012

Intelligence-collection group focused on Korean Peninsula policy experts and US think tanks, using elaborate spearphishing and credential-harvesting personas.

Aliases
Velvet ChollimaEmerald SleetAPT43
Primary targets
Think tanks Korean Peninsula policy experts Government officials Journalists

MITRE ATT&CK techniques

0 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.

No MITRE ATT&CK mapping available yet for Kimsuky.

Curated incidents

  1. 2020-10-28·Government / Think Tanks·United States, South Korea
    CISA warns Kimsuky targeting US think tanks on Korean Peninsula policy

    Joint advisory describes global intelligence-gathering campaign against experts and organizations focused on North Korea policy.