logo

Kimsuky__2021__as-21-Kuo-We-Are-About-To-Land-How-CloudDragon-Turns-A-Nightmare-Into-Reality.pdf

ID: f31450c7-e600-4b6f-8029-3a4cd8343902

STIX ID: report--f31450c7-e600-4b6f-8029-3a4cd8343902

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2021-04-21

Last Modified Date: 2021-04-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
CloudDragon (linked to Kimsuky/APT activity) is a multi-year, multi-platform APT campaign that uses supply-chain compromise, targeted phishing (proxy-mirror), and malware families (JamBog, BabyShark, TroiBomb, RoastMe, DongMulRAT) to exfiltrate data and steal cryptocurrency; the report documents infrastructure (domains, IPs), sample hashes, code snippets showing credential/seed harvesting and SMS exfiltration, and an August–October 2020 incident impersonating a hardware wallet update to steal mnemonic seeds.