kimsuky-2023-03-20-joint-cyber-security-advisory.pdf
ID: 166f95df-9746-4093-9964-824029406eae
STIX ID: report--166f95df-9746-4093-9964-824029406eae
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2023-03-10
Last Modified Date: 2023-03-10
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Joint advisory from Germany's BfV and South Korea's NIS warns that the APT actor KIMSUKY (aka Thallium/Velvet Chollima) is conducting spear-phishing campaigns that deploy malicious Chromium browser extensions to steal Gmail contents and abuse Google Play synchronization to install malicious Android apps; the report includes TTPs, IoCs (C2 domains, file hashes, app identifiers), and recommended mitigations.
