The "Kimsuky" Operation: A North Korean APT?
ID: cf0526f8-188d-4464-9c7b-0cd3c315c2ba
STIX ID: report--cf0526f8-188d-4464-9c7b-0cd3c315c2ba
Threat Score
75/100
Uploaded: 2026-08-21
Published Date: 2014-07-15
Last Modified Date: 2014-07-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Kimsuky operation describes a North Korean APT campaign that targeted South Korean think tanks using a multi-stage malware loader and espionage modules for keystroke logging, data collection, and exfiltration, with persistence and C2 communications via Bulgarian email servers; the campaign includes HWP document stealing, remote control capabilities, and multiple indicators of compromise, highlighting a sophisticated, state-sponsored threat actor activity.
