Kimsuky

APT / StateG0094
Origin🇰🇵 Coreia do Norte
Techniques (MITRE ATT&CK)130
SourceMITRE ATT&CK
State sponsor: Korea (Democratic People's Republic of)Attribution confidence: 50%Target categories: Government, Private sector
Targeted regions: Ministry of Unification · Sejong Institute · Korea Institute for Defense Analyses · Germany
Also known as:Black BansheeVelvet ChollimaEmerald SleetTHALLIUMAPT43TA427SpringtailEarth KumihoPatheticSlug

Vexday analysis

Kimsuky é um grupo de espionagem cibernética originário da Coreia do Norte (DPRK), ativo pelo menos desde 2012 e rastreado pelo MITRE ATT&CK sob o identificador G0094 — também referenciado pelos aliases Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43 e TA427. O grupo iniciou suas operações visando agências governamentais sul-coreanas, think tanks e especialistas temáticos, expandindo posteriormente seu escopo para abranger a ONU e organizações nos setores governamental, educacional, de serviços empresariais e manufatureiro nos Estados Unidos, Japão, Rússia e Europa. Suas coletas são focadas em questões de política externa e segurança nacional relacionadas à Península Coreana, política nuclear e sanções internacionais. Ao grupo são atribuídas 3 CVEs conhecidas e 130 técnicas documentadas no framework MITRE ATT&CK.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity86
Impact: High
T1190T1053.005T1098.007T1546.001T1005T1020ENTRYInitial accessExploitPublic-Facing App…EXECExecutionScheduled TaskPERSPersistenceAdditional Localor Domain GroupsPRIVPrivilege escalationChange DefaultFile AssociationCOLLCollectionData from LocalSystemEXFILExfiltrationAutomatedExfiltrationIMPACTImpactService Stop

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 130

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 3

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 39

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

domainuybwveyvyt62rc.siteAmadeythreatfox
domainzsv2c62243.spaceAmadeythreatfox
md5_hash82617293c095f7170bea3d3384f8da2bAmadeythreatfox
md5_hash7b0e7c8cc9ca514381a6bfecf879b650Amadeythreatfox
sha1_hashe1c1a8a9d67b3dc8cdce7f357dedf81cfe360ec1Amadeythreatfox
sha256_hash3fed685e1b41d37f28a2fbd69ee3755ab4797b5d9b60ca6d904b2c9529af12f8Amadeythreatfox
sha1_hashdc665280d55c2a5393282a7c207a9adfa65d0472Amadeythreatfox
sha256_hashaa3ec6bd662f64b5471ba79945d9e620adb66cae5e2887e44eea03d8abc99c73Amadeythreatfox
sha1_hash5ae3941fddd55e92eb7bab8c1b9bc5f4b9fa7d70Amadeythreatfox
md5_hash262373e7649042b5541bcab907599a71Amadeythreatfox
sha256_hash5f160eb9a281a5f2a1a6ea1c5743d34fd3c0f1c34407ea1bd2d197e64cfa8c3cAmadeythreatfox
urlhttp://196.251.107.186/build_x32.exeAmadeyurlhaus
md5_hashf8e68cddf13a94d821a4b265172a0e32Amadeythreatfox
sha256_hashe85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52Amadeythreatfox
sha1_hash16646bfd7f6554cd170fb373ce813c24f37e829eAmadeythreatfox
md5_hash5d11d7b9b175695c197014bc6aa2fbdbAmadeythreatfox
sha256_hasha86c023a02f1454738b39f753f50777c238b4ea296ffc76cd41c3059f216be10Amadeythreatfox
sha1_hashc25b20a5f15a0f69e0343b539bb4408a4e3739dbAmadeythreatfox
sha256_hasha86c023a02f1454738b39f753f50777c238b4ea296ffc76cd41c3059f216be10Amadeymalwarebazaar
urlhttp://192.162.199.186/aB7xTy2N/mAjOR.phpAmadeythreatfox
sha256_hashe85149704da6ee8f9bc1c55304c560d1a792180489d4859a64cf0a4e056ccf52Amadeymalwarebazaar
urlhttp://196.251.107.186/qK3mRv9L/pLdWr.phpAmadeythreatfox
sha256_hash267e3d1dc9718ec99fecad28a3f4ec24100d8b0e2c60701289681e39d85fd3dbAmadeymalwarebazaar
ip:port37.1.213.59:80Amadeythreatfox
urlhttp://37.1.213.59/y8jdGc5jS/Plugins/cred.dllAmadeyurlhaus
urlhttp://37.1.213.59/y8jdGc5jS/Plugins/cred64.dllAmadeyurlhaus
urlhttp://37.1.213.59/y8jdGc5jS/index.phpAmadeythreatfox
urlhttp://196.251.107.104/NuclearBomb.exeAmadeyurlhaus
urlhttp://196.251.107.104/sprd2.exeAmadeyurlhaus
urlhttp://196.251.107.104/bot_x64.exeAmadeyurlhaus

+39 indicators in total. See them all on the IOCs page.

Kimsuky uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →