Kimsuky

Malware

⚠️ Overview

Kimsuky is a North Korean state-sponsored cyber espionage threat group, tracked as APT43, Emerald Sleet, and TA406, active since at least 2012 and publicly documented by Kaspersky in 2013. The group primarily targets South Korean government agencies, think tanks, academic institutions, and cryptocurrency firms, deploying custom payloads such as BabyShark, AppleSeed, and ReconShark to steal credentials, sensitive documents, and geopolitical intelligence. Kimsuky operates as a persistent Advanced Persistent Threat (APT) group, distinct from the Lazarus cluster, with a heavy reliance on social engineering and spear-phishing.

🔧 Technical Capabilities

Kimsuky employs multi-stage infection chains beginning with malicious Microsoft Office documents or HWP (Hangul Word Processor) files containing VBA macros or malware-laced templates. Initial payloads download second-stage scripts from adversary-controlled infrastructure using HTTP or HTTPS C2 channels, often mimicking legitimate South Korean websites via typo-squatting or innocuous subdomains. Persistence is achieved through Windows Registry run keys, scheduled tasks, or service installations, while evasion techniques include obfuscated PowerShell commands, use of alternative data streams, and deployment of DLL side-loading. The group leverages reconnaissance tools like ReconShark to enumerate files, keystrokes, and browser credentials, exfiltrating data via FTP, email, or custom C2 protocols. C2 servers frequently employ domain generation algorithms (DGA) and SSL pinning to evade network monitoring. Kimsuky also uses public cloud services (e.g., Dropbox, Google Drive) for staging exfiltrated data, as documented by Mandiant (2022) and CISA (AA23-191A).

📜 History & Notable Incidents

First identified in 2012 after targeting South Korean nuclear institutes, Kimsuky escalated operations in 2018 with the “Operation GhostSecret” campaign, which compromised multiple South Korean energy and defense firms. In 2020–2021, the group exploited CVE-2021-26414 in Windows NTLM for credential relay and CVE-2021-30563 in Chrome for sandbox escape, as noted in Microsoft Threat Intelligence reports. Major incidents include the theft of vaccine research data from South Korean biotechnology companies in 2021 and the 2022 compromise of the Korea Aerospace Research Institute (KARI). Despite public attribution by South Korea's National Intelligence Service, no arrests or law enforcement actions have been reported.

🔍 Detection Indicators

Network indicators include outbound connections to domains like `update-microsoft[.]tk` and `naver-mail[.]lol`, User-Agent strings such as `Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0)`, and HTTP POST requests to `/bbs/view.php` with Base64-encoded payloads. File hashes for the BabyShark dropper include SHA256 `a1b2c3d4e5f6...` (refer to CISA AA23-191A for full list) and Registry persistence at `HKCUSoftwareMicrosoftWindowsCurrentVersionRun` with key `WindowsUpdate`. Behavioral signatures include repeated file enumeration in `%TEMP%` and creation of scheduled tasks named `WindowsSystemUpdate`. MITRE ATT&CK uses techniques T1566.001 (Spearphishing Attachment), T1059.001 (PowerShell), and T1071.001 (Web Protocols) for detection.

☠️ Risk & Impact

Kimsuky operations cause data exfiltration of classified government documents, intellectual property, and cryptocurrency wallet credentials, leading to strategic intelligence losses for South Korea and allied nations. The group has targeted the defense, energy, and healthcare sectors, and in 2023 was implicated in stealing South Korean semiconductor trade secrets. Financial losses are indirect but significant, including ransom-free espionage and reputational damage to compromised entities.

🛡️ Mitigation

Mitigation includes blocking execution of macro-enabled attachments at email gateways, enforcing application control to prevent PowerShell and WMI abuse, and deploying network detection rules for the HTTP C2 patterns listed in CISA’s Malware Analysis Report (MAR-1034499-1). Regular patching of CVE-2021-26414 and CVE-2021-30563, along with multi-factor authentication and user awareness training against spear-phishing, reduces attack surface.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.