logo

The "Kimsuky" Operation: A North Korean APT?

ID: cf0526f8-188d-4464-9c7b-0cd3c315c2ba

STIX ID: report--cf0526f8-188d-4464-9c7b-0cd3c315c2ba

Threat Score

75/100

Uploaded: 2026-08-21

Published Date: 2014-07-15

Last Modified Date: 2014-07-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Kimsuky operation describes a North Korean APT campaign that targeted South Korean think tanks using a multi-stage malware loader and espionage modules for keystroke logging, data collection, and exfiltration, with persistence and C2 communications via Bulgarian email servers; the campaign includes HWP document stealing, remote control capabilities, and multiple indicators of compromise, highlighting a sophisticated, state-sponsored threat actor activity.