Kimsuky__2020__TLP-WHITE_AA20-301A_North_Korean_APT_Focus_Kimsuky.pdf
ID: 726aa979-e4bb-4442-b211-5d30873a83f0
STIX ID: report--726aa979-e4bb-4442-b211-5d30873a83f0
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2020-10-27
Last Modified Date: 2020-10-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This CISA/FBI/CNMF joint advisory details the tactics, techniques, and procedures of the North Korean APT "Kimsuky," including spearphishing lures, BabyShark VBS and other implants, credential harvesting (browser extension abuse, keyloggers, ProcDump), persistence (registry run keys, services, malicious browser extensions), process injection and privilege escalation, modified TeamViewer for C2, observed domains and file/path IOCs, and mitigations such as MFA and phishing defenses.
