G0094

G0094Kimsuky

Description

[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially focused on targeting South Korean government entities, think tanks, and individuals identified as experts in various fields, and expanded its operations to include the United States, Russia, Europe, and the UN. [Kimsuky](https://attack.mitre.org/groups/G0094) has focused its intelligence collection activities on foreign policy and national security issues related to the Korean peninsula, nuclear policy, and sanctions.(Citation: EST Kimsuky April 2019)(Citation: BRI Kimsuky April 2019)(Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: CISA AA20-301A Kimsuky) [Kimsuky](https://attack.mitre.org/groups/G0094) was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).(Citation: Netscout Stolen Pencil Dec 2018)(Citation: EST Kimsuky SmokeScreen April 2019)(Citation: AhnLab Kimsuky Kabar Cobra Feb 2019) North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name [Lazarus Group](https://attack.mitre.org/groups/G0032) instead of tracking clusters or subgroups.

References

  1. https://attack.mitre.org/groups/G0094
  2. https://global.ahnlab.com/global/upload/download/techreport/%5BAnalysis_Report%5DOperation%20Kabar%20Cobra.pdf
  3. https://blog.alyac.co.kr/2234
  4. https://asert.arbornetworks.com/stolen-pencil-campaign-targets-academia/
  5. https://brica.de/alerts/alert/public/1255063/kimsuky-unveils-apt-campaign-smoke-screen-aimed-at-korea-and-america/
  6. https://www.zdnet.com/article/cyber-espionage-group-uses-chrome-extension-to-infect-victims/
  7. https://us-cert.cisa.gov/ncas/alerts/aa20-301a
  8. https://www.cybereason.com/blog/back-to-the-future-inside-the-kimsuky-kgh-spyware-suite
  9. https://blog.alyac.co.kr/attachment/cfile5.uf@99A0CD415CB67E210DCEB3.pdf
  10. https://blog.malwarebytes.com/threat-analysis/2021/06/kimsuky-apt-continues-to-target-south-korean-government-using-appleseed-backdoor/

Software attributed to this3

TypeTargetConfidenceTier
SoftwareAppleSeeds0622100%live
SoftwareKGH_SPYs0526100%live
SoftwareCSPY Downloaders0527100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Group
Stolen Pencil
Group
Higaisa
Group
Lazarus Group
Group
APT37
Actor
APT43
Group
Gelsemium
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.