logo

Kimsuky__2020__TLP-WHITE_AA20-301A_North_Korean_APT_Focus_Kimsuky.pdf

ID: 726aa979-e4bb-4442-b211-5d30873a83f0

STIX ID: report--726aa979-e4bb-4442-b211-5d30873a83f0

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2020-10-27

Last Modified Date: 2020-10-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This CISA/FBI/CNMF joint advisory details the tactics, techniques, and procedures of the North Korean APT "Kimsuky," including spearphishing lures, BabyShark VBS and other implants, credential harvesting (browser extension abuse, keyloggers, ProcDump), persistence (registry run keys, services, malicious browser extensions), process injection and privilege escalation, modified TeamViewer for C2, observed domains and file/path IOCs, and mitigations such as MFA and phishing defenses.