🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
KIMSUKY (APT43)

/actor/kimsuky-apt43/  ·  0 intel reports

Year Established
2012
Attribution
North Korea (RGB)
Motivation
Espionage, Policy Intelligence, Nuclear Monitoring
Modus Operandi (MO)
Spear-phishing, fake think tank personas, Korean peninsula policy researcher targeting
Primary Aliases
APT43, Velvet Chollima, Thallium, Black Banshee, Emerald Sleet

Kimsuky, also designated APT43, is a North Korean state-sponsored threat actor attributed to the Reconnaissance General Bureau (RGB) with a primary mandate focused on intelligence collection supporting North Korean foreign policy and strategic decision-making , particularly regarding denuclearisation negotiations, US-ROK military alliance activities, and international sanctions policy. The group specialises in targeting Korean peninsula policy researchers, think tanks, academic institutions, and government officials with expertise in North Korean affairs.

Kimsuky's hallmark social engineering technique involves the creation of elaborate fake personas , mimicking credible academics, journalists, think tank researchers, or government officials , to approach targets with requests for interviews, policy papers, or conference participation. These persona-based approaches allow the group to establish trust before delivering credential-harvesting links or malware-laden documents, often with remarkably convincing supporting infrastructure including fake institutional websites, LinkedIn profiles, and business email addresses.

The group has demonstrated sustained interest in nuclear policy experts, targeting individuals involved in Track 2 diplomacy with North Korea, former US and South Korean government officials with North Korea expertise, and journalists covering Korean peninsula security affairs. By maintaining access to these individuals' email accounts and personal devices, Kimsuky provides the Kim regime with real-time intelligence on how key foreign policy actors are thinking about North Korea and what information they are sharing in private communications.

Beyond espionage, Kimsuky conducts financially motivated cryptocurrency theft operations to generate hard currency for the regime, and has been linked to spear-phishing campaigns targeting South Korean cryptocurrency exchanges. The US Department of Treasury sanctioned Kimsuky in 2023 following their targeting of five nuclear nations' government officials in connection with North Korea's ballistic missile programme.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Kimsuky (APT43) requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles