🇰🇵Kimsuky
🇰🇵 Kimsuky is a tracked threat actor in the Clankerusecase corpus. Attributed to KP. Primary motivation: State. We map 26 detection use cases to this actor across 143 MITRE ATT&CK techniques, with 3 threat-intel articles citing them. Active in our corpus from 2025-11-06 to 2026-05-28.
crit 3
26Use cases
3Articles
143Techniques
1IOCs
Known aliases
KimsukyVelvet ChollimaBlack BansheeThalliumEmerald SleetTHALLIUMAPT43TA427SpringtailEarth KumihoPatheticSlug
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1007 · System Service DiscoveryT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1020 · Automated ExfiltrationT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.001 · Binary PaddingT1027.002 · Software PackingT1027.007 · Dynamic API ResolutionT1027.010 · Command ObfuscationT1027.012 · LNK Icon SmugglingT1027.013 · Encrypted/Encoded FileT1027.015 · CompressionT1027.016 · Junk Code InsertionT1033 · System Owner/User DiscoveryT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1036.007 · Double File ExtensionT1040 · Network SniffingT1041 · Exfiltration Over C2 ChannelT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.001 · Dynamic-link Library InjectionT1055.012 · Process HollowingT1056.001 · KeyloggingT1056.003 · Web Portal CaptureT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1059.007 · JavaScriptT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.002 · File Transfer ProtocolsT1071.003 · Mail ProtocolsT1071.004 · DNST1074.001 · Local Data StagingT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1098.007 · Additional Local or Domain GroupsT1102.001 · Dead Drop ResolverT1102.002 · Bidirectional CommunicationT1105 · Ingress Tool TransferT1106 · Native APIT1111 · Multi-Factor Authentication InterceptionT1112 · Modify RegistryT1113 · Screen CaptureT1114.002 · Remote Email CollectionT1114.003 · Email Forwarding RuleT1115 · Clipboard DataT1124 · System Time DiscoveryT1132.002 · Non-Standard EncodingT1133 · External Remote ServicesT1136.001 · Local AccountT1140 · Deobfuscate/Decode Files or InformationT1176.001 · Browser ExtensionsT1185 · Browser Session HijackingT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.004 · Malicious Copy and PasteT1205 · Traffic SignalingT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1218.005 · MshtaT1218.010 · Regsvr32T1218.011 · Rundll32T1219 · Remote Access ToolsT1219.002 · Remote Desktop SoftwareT1480.002 · Mutual ExclusionT1486 · Data Encrypted for ImpactT1489 · Service StopT1497.001 · System ChecksT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1534 · Internal SpearphishingT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1546.001 · Change Default File AssociationT1546.016 · Installer PackagesT1547.001 · Registry Run Keys / Startup FolderT1550.002 · Pass the HashT1552.001 · Credentials In FilesT1552.004 · Private KeysT1553.002 · Code SigningT1555.003 · Credentials from Web BrowsersT1557 · Adversary-in-the-MiddleT1559.001 · Component Object ModelT1560.001 · Archive via UtilityT1560.003 · Archive via Custom MethodT1564.002 · Hidden UsersT1564.003 · Hidden WindowT1564.011 · Ignore Process InterruptsT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1567.002 · Exfiltration to Cloud StorageT1568 · Dynamic ResolutionT1568.002 · Domain Generation AlgorithmsT1569.002 · Service ExecutionT1574.002 · T1574.002T1583 · Acquire InfrastructureT1583.001 · DomainsT1583.004 · ServerT1583.006 · Web ServicesT1584.001 · DomainsT1585 · Establish AccountsT1585.001 · Social Media AccountsT1585.002 · Email AccountsT1586.002 · Email AccountsT1587 · Develop CapabilitiesT1587.001 · MalwareT1588.002 · ToolT1588.003 · Code Signing CertificatesT1588.005 · ExploitsT1589.002 · Email AddressesT1589.003 · Employee NamesT1591 · Gather Victim Org InformationT1593.001 · Social MediaT1593.002 · Search EnginesT1594 · Search Victim-Owned WebsitesT1596 · Search Open Technical DatabasesT1598 · Phishing for InformationT1598.003 · Spearphishing LinkT1608.001 · Upload MalwareT1620 · Reflective Code LoadingT1657 · Financial TheftT1678 · Delay ExecutionT1680 · Local Storage DiscoveryT1682 · Query Public AI ServicesT1684.001 · ImpersonationT1685 · Disable or Modify ToolsT1686 · Disable or Modify System Firewall
Detection use cases (26)
Kimsuky (APT43 / Emerald Sleet) CHM-delivered execution: hh.exe spawning script engines for AppleSeed/BabyShark stager Kimsuky (APT43 / TA427) mailbox exfil: Exchange/M365 auto-forwarding rule to external address on policy-research target Trojanized axios npm package postinstall: node.exe spawned from plain-crypto-js dependency axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging axios RAT C2 callout to sfrclak.com / 142.11.206.73:8000 Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movement Trusted vendor binary / installer launching unusual children Kimsuky HelloDoor 'tdll' Run-key persistence with regsvr32 loader Kimsuky httpMalice persistence: 'Everything 1.9a-/1.8a-' Run-key or CacheDB service install Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public EgressThreat-intel articles (3)
crit ESET APT Activity Report Q4 2025–Q1 2026 · 2026-05-28
crit ESET APT Activity Report Q2 2025–Q3 2025 · 2025-11-06
Tracked indicators
Domains (1)
female-disorder-beta-metCVEs (2)
CVE-2024-42009 CVE-2025-8088