KPKorea (Democratic People's Republic of)confidence: 50G0094
KimsukyKimsuky
Also known as: Velvet Chollima · Black Banshee · Thallium · Operation Stolen Pencil · G0086 · APT43 · Emerald Sleet · THALLIUM · Springtail · Sparkling Pisces · Kimsuky
Origin
KP
Known aliases
11
Target sectors
2
Attribution
State-sponsored
Profile
Kimsuky is a North Korean-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Velvet Chollima, Black Banshee, Thallium (and 7 more). Operational targeting focuses on the Government and Private sector sectors. Documented victim organisations include Ministry of Unification, Sejong Institute, Korea Institute for Defense Analyses and 1 other named victims. Original record: This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.
Aliases· 11
Velvet ChollimaBlack BansheeThalliumOperation Stolen PencilAPT43Emerald SleetTHALLIUMSpringtailSparkling PiscesKimsuky
Target sectors· 2
GovernmentPrivate sector
Known victims· 4
- Ministry of Unification
- Sejong Institute
- Korea Institute for Defense Analyses
- Germany
MITRE ATT&CK Group crosswalk
References
- https://securelist.com/the-kimsuky-operation-a-north-korean-apt/57915/
- https://www.cfr.org/interactive/cyber-operations/kimsuky
- https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/tracking-kimsuky-north-korea-based-cyber-espionage-group-part-2.html
- https://youtu.be/hAsKp43AZmM?t=1027
- https://www.bloomberglaw.com/document/public/subdoc/X67FPNDOUBV9VOPS35A4864BFIU?imagename=1
- https://www.netscout.com/blog/asert/stolen-pencil-campaign-targets-academia
- https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/
- https://attack.mitre.org/groups/G0086/
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.