{"id":434,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2012<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">North Korea (RGB)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Espionage, Policy Intelligence, Nuclear Monitoring<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Spear-phishing, fake think tank personas, Korean peninsula policy researcher targeting<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">APT43, Velvet Chollima, Thallium, Black Banshee, Emerald Sleet<\/div>\n  <\/div>\n<\/div>\n<p>Kimsuky, also designated APT43, is a North Korean state-sponsored threat actor attributed to the Reconnaissance General Bureau (RGB) with a primary mandate focused on intelligence collection supporting North Korean foreign policy and strategic decision-making ,  particularly regarding denuclearisation negotiations, US-ROK military alliance activities, and international sanctions policy. The group specialises in targeting Korean peninsula policy researchers, think tanks, academic institutions, and government officials with expertise in North Korean affairs.<\/p>\n<p>Kimsuky's hallmark social engineering technique involves the creation of elaborate fake personas ,  mimicking credible academics, journalists, think tank researchers, or government officials ,  to approach targets with requests for interviews, policy papers, or conference participation. These persona-based approaches allow the group to establish trust before delivering credential-harvesting links or malware-laden documents, often with remarkably convincing supporting infrastructure including fake institutional websites, LinkedIn profiles, and business email addresses.<\/p>\n<p>The group has demonstrated sustained interest in nuclear policy experts, targeting individuals involved in Track 2 diplomacy with North Korea, former US and South Korean government officials with North Korea expertise, and journalists covering Korean peninsula security affairs. By maintaining access to these individuals' email accounts and personal devices, Kimsuky provides the Kim regime with real-time intelligence on how key foreign policy actors are thinking about North Korea and what information they are sharing in private communications.<\/p>\n<p>Beyond espionage, Kimsuky conducts financially motivated cryptocurrency theft operations to generate hard currency for the regime, and has been linked to spear-phishing campaigns targeting South Korean cryptocurrency exchanges. The US Department of Treasury sanctioned Kimsuky in 2023 following their targeting of five nuclear nations' government officials in connection with North Korea's ballistic missile programme.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>Kimsuky (APT43)<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/kimsuky-apt43\/","name":"Kimsuky (APT43)","slug":"kimsuky-apt43","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/434","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=434"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}