logo

kimsuky-2023-03-20-joint-cyber-security-advisory.pdf

ID: 166f95df-9746-4093-9964-824029406eae

STIX ID: report--166f95df-9746-4093-9964-824029406eae

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2023-03-10

Last Modified Date: 2023-03-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Joint advisory from Germany's BfV and South Korea's NIS warns that the APT actor KIMSUKY (aka Thallium/Velvet Chollima) is conducting spear-phishing campaigns that deploy malicious Chromium browser extensions to steal Gmail contents and abuse Google Play synchronization to install malicious Android apps; the report includes TTPs, IoCs (C2 domains, file hashes, app identifiers), and recommended mitigations.