Kimsuky
Also reported as Black Banshee, Emerald Sleet, Velvet Chollima, THALLIUM, APT43 and 26 other names. Linked to North Korea by four sources.
Reports per quarter
Techniques seen in the last two years
- T1566.001 8 reports in ATT&CK
- T1027 6 reports in ATT&CK
- T1059.001 5 reports in ATT&CK
- T1071.001 5 reports in ATT&CK
- T1082 5 reports in ATT&CK
- T1140 5 reports in ATT&CK
- T1566.002 5 reports in ATT&CK
- T1041 4 reports in ATT&CK
- T1190 4 reports in ATT&CK
- T1204.002 4 reports in ATT&CK
Show all 114 techniques Show fewer
- T1547.001 4 reports in ATT&CK
- T1056.001 3 reports in ATT&CK
- T1070.004 3 reports in ATT&CK
- T1083 3 reports in ATT&CK
- T1091 3 reports reports only
- T1112 3 reports in ATT&CK
- T1195 3 reports reports only
- T1620 3 reports in ATT&CK
- T1659 3 reports reports only
- T1005 2 reports in ATT&CK
- T1012 2 reports in ATT&CK
- T1036 2 reports reports only
- T1036.005 2 reports in ATT&CK
- T1053 2 reports reports only
- T1057 2 reports in ATT&CK
- T1059.003 2 reports in ATT&CK
- T1059.005 2 reports in ATT&CK
- T1059.007 2 reports in ATT&CK
- T1132 2 reports reports only
- T1189 2 reports reports only
- T1417.001 2 reports reports only
- T1418 2 reports reports only
- T1497.001 2 reports in ATT&CK
- T1541 2 reports reports only
- T1555.003 2 reports in ATT&CK
- T1560 2 reports reports only
- T1566.003 2 reports reports only
- T1598 2 reports in ATT&CK
- T1646 2 reports reports only
- T1660 2 reports in ATT&CK
- T1001 1 report reports only
- T1003 1 report reports only
- T1016 1 report in ATT&CK
- T1025 1 report reports only
- T1027.002 1 report in ATT&CK
- T1027.010 1 report in ATT&CK
- T1033 1 report in ATT&CK
- T1036.001 1 report reports only
- T1036.007 1 report in ATT&CK
- T1037.001 1 report reports only
- T1048.003 1 report reports only
- T1053.003 1 report reports only
- T1053.005 1 report in ATT&CK
- T1055 1 report in ATT&CK
- T1056.003 1 report in ATT&CK
- T1069 1 report reports only
- T1070 1 report reports only
- T1071 1 report reports only
- T1071.004 1 report reports only
- T1098 1 report reports only
- T1102 1 report reports only
- T1102.001 1 report in ATT&CK
- T1105 1 report in ATT&CK
- T1113 1 report in ATT&CK
- T1115 1 report in ATT&CK
- T1132.001 1 report reports only
- T1132.002 1 report in ATT&CK
- T1134 1 report reports only
- T1195.002 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.004 1 report in ATT&CK
- T1212 1 report reports only
- T1218.005 1 report in ATT&CK
- T1218.010 1 report in ATT&CK
- T1218.011 1 report in ATT&CK
- T1398 1 report reports only
- T1406 1 report reports only
- T1420 1 report reports only
- T1426 1 report reports only
- T1429 1 report reports only
- T1437 1 report reports only
- T1497 1 report reports only
- T1512 1 report reports only
- T1518.001 1 report in ATT&CK
- T1532 1 report reports only
- T1550.004 1 report reports only
- T1555 1 report reports only
- T1557 1 report in ATT&CK
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566 1 report in ATT&CK
- T1567.002 1 report in ATT&CK
- T1573 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.014 1 report reports only
- T1575 1 report reports only
- T1585.001 1 report in ATT&CK
- T1585.002 1 report in ATT&CK
- T1587.001 1 report in ATT&CK
- T1588 1 report reports only
- T1588.004 1 report reports only
- T1589 1 report reports only
- T1592 1 report reports only
- T1608 1 report reports only
- T1608.003 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1616 1 report reports only
- T1622 1 report reports only
- T1636.002 1 report reports only
- T1636.003 1 report reports only
- T1636.004 1 report reports only
- T1655.001 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
Show all 79 techniques Show fewer
- T1055.001
- T1055.012
- T1059.006
- T1070.006
- T1071.002
- T1071.003
- T1074.001
- T1078.003
- T1098.007
- T1102.002
- T1106
- T1111
- T1114.002
- T1114.003
- T1124
- T1133
- T1136.001
- T1176.001
- T1185
- T1205
- T1217
- T1219.002
- T1480.002
- T1489
- T1505.003
- T1534
- T1539
- T1543.003
- T1546.001
- T1550.002
- T1552.001
- T1552.004
- T1553.002
- T1559.001
- T1560.001
- T1560.003
- T1564.002
- T1564.003
- T1564.011
- T1568
- T1583
- T1583.001
- T1583.004
- T1583.006
- T1584.001
- T1585
- T1586.002
- T1587
- T1588.002
- T1588.003
- T1588.005
- T1589.002
- T1589.003
- T1591
- T1593.001
- T1593.002
- T1594
- T1596
- T1598.003
- T1608.001
- T1657
- T1678
- T1680
- T1682
- T1684.001
- T1685
- T1686
CVEs named in reports
- CVE-2008-2463
- CVE-2012-0158 KEV ransomware
- CVE-2012-4873
- CVE-2012-5687
- CVE-2013-3900 KEV
- CVE-2013-4979
- CVE-2013-5947
- CVE-2014-0497 KEV
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
Show all 195 CVEs Show fewer
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2545 KEV
- CVE-2015-3105
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0147
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-4171 KEV
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-0261 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-8291 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-14745
- CVE-2018-1579
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2628 KEV
- CVE-2018-4878 KEV ransomware
- CVE-2018-6055
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8405 KEV ransomware
- CVE-2018-8406 KEV ransomware
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0797 KEV
- CVE-2019-0808 KEV
- CVE-2019-0859 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-1132 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11707 KEV
- CVE-2019-11708 KEV
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-17026 KEV
- CVE-2019-1821
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2215 KEV
- CVE-2019-3568 KEV
- CVE-2019-5786 KEV
- CVE-2019-6225
- CVE-2019-7286 KEV
- CVE-2019-7287 KEV
- CVE-2019-8518
- CVE-2019-9670 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-12641 KEV
- CVE-2020-1300
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-15782
- CVE-2020-1664
- CVE-2020-2021 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6418 KEV
- CVE-2020-6819 KEV
- CVE-2020-6820 KEV
- CVE-2020-8467 KEV
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-36958
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44026 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0609 KEV
- CVE-2022-1388 KEV ransomware
- CVE-2022-21587 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-27925 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-5631 KEV
- CVE-2024-11182 KEV
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-21413 KEV
- CVE-2024-21887 KEV ransomware
- CVE-2024-26229
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36991
- CVE-2024-38080 KEV
- CVE-2024-38112 KEV
- CVE-2024-40766 KEV ransomware
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-4885 KEV
- CVE-2024-49039 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
- CVE-2024-9680 KEV ransomware
- CVE-2025-0282 KEV ransomware
- CVE-2025-10035 KEV ransomware
- CVE-2025-12562
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
- CVE-2025-5777 KEV ransomware
- CVE-2025-61882 KEV ransomware
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
- CVE-2026-1281 KEV
- CVE-2026-1340 KEV
- CVE-2026-21509 KEV
- CVE-2026-22813
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 322 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Amadey (Malware Family)
-
Kimsuky, Velvet Chollima - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Kimsuky, Velvet Chollima - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Meterpreter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Kimsuky (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Quasar RAT (Malware Family)
-
Reaper, APT 37, Ricochet Chollima, ScarCruft
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Reaper, APT 37, Ricochet Chollima, ScarCruft
-
(3) Kimsuky is targeting an arms manufacturer in Europe. | LinkedIn
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor (3) Kimsuky is targeting an arms manufacturer in Europe. | LinkedIn
-
Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
-
Kimsuky Group Uses AutoIt to Create Malware (RftRAT, Amadey)
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Kimsuky Group Uses AutoIt to Create Malware (RftRAT, Amadey)
-
Kimsuky - Ongoing Campaign Using Tailored Reconnaissance Toolkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky - Ongoing Campaign Using Tailored Reconnaissance Toolkit
-
Detailed Analysis of AlphaSeed, a new version of Kimsuky’s AppleSeed written in Golang
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detailed Analysis of AlphaSeed, a new version of Kimsuky’s AppleSeed written in Golang
-
Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 3CX Software Supply Chain Compromise Initiated by a Prior Software Supply Chain Compromise; Suspected North Korean Actor Responsible
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering nation state watering hole credential harvesting campaigns targeting human rights activists by APT threat group UCID902
-
APT43 An investigation into the North Korean group's cybercrime operations
The title opens a link whose publisher is not confirmed. Detailsfor APT43 An investigation into the North Korean group's cybercrime operations
-
How we’re protecting users from government-backed attacks from North Korea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How we’re protecting users from government-backed attacks from North Korea
-
APT43- North Korean Group Uses Cybercrime to Fund Espionage Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT43- North Korean Group Uses Cybercrime to Fund Espionage Operations
-
Kimsuky group distributes malware disguised as a profile file (GitHub)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky group distributes malware disguised as a profile file (GitHub)
-
Kimsuky group appears to be exploiting OneNote like the cybercrime group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky group appears to be exploiting OneNote like the cybercrime group
-
(FINAL)NIS-BfV JoinCyberSecurityAdvisory(DE)
The original link failed its last check. Original publisher Detailsfor (FINAL)NIS-BfV JoinCyberSecurityAdvisory(DE)
-
CHM malware (Kimsuky) disguised questionnaires related to North Korea
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CHM malware (Kimsuky) disguised questionnaires related to North Korea
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Threat Report- RambleOn Android Malware - Detailed analysis report of cyber threat targeting journalist in South Korea through APT phishing campaign with malicious APK
-
The DPRK delicate sound of cyber
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The DPRK delicate sound of cyber
-
North Korean cyber spies deploy new tactic- tricking foreign experts into writing research for them
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean cyber spies deploy new tactic- tricking foreign experts into writing research for them
-
Detailing Daily Domain Hunting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detailing Daily Domain Hunting
-
Appleseed Being Distributed to Nuclear Power Plant-Related Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Appleseed Being Distributed to Nuclear Power Plant-Related Companies
-
Unveil the evolution of Kimsuky targeting Android devices with newly discovered mobile malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Unveil the evolution of Kimsuky targeting Android devices with newly discovered mobile malware
-
Kimsuky’s GoldDragon cluster and its C2 operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky’s GoldDragon cluster and its C2 operations
-
Word File Provided as External Link When Replying to Attacker’s Email (Kimsuky)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Word File Provided as External Link When Replying to Attacker’s Email (Kimsuky)
-
LofyLife- malicious npm packages steal Discord tokens and bank card data
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor LofyLife- malicious npm packages steal Discord tokens and bank card data
-
Dissemination of AppleSeed to Specific Military Maintenance Companies
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dissemination of AppleSeed to Specific Military Maintenance Companies
-
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AppleSeed Disguised as Purchase Order and Request Form Being Distributed
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
VBS Script Disguised as PDF File Being Distributed (Kimsuky)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VBS Script Disguised as PDF File Being Distributed (Kimsuky)
-
Not So Lazarus- Mapping DPRK Cyber Threat Groups to Government Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Not So Lazarus- Mapping DPRK Cyber Threat Groups to Government Organizations
-
BitRAT Disguised as Windows Product Key Verification Tool Being Distributed
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BitRAT Disguised as Windows Product Key Verification Tool Being Distributed
-
Distribution of Kimsuky Group’s xRAT (Quasar RAT) Confirmed
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Distribution of Kimsuky Group’s xRAT (Quasar RAT) Confirmed
-
Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Patchwork_Patchwork-APT-caught-in-its-own-web_MalwarebytesLabs
-
Analysis Report on Kimsuky Group’s APT Attacks (AppleSeed, PebbleDash)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis Report on Kimsuky Group’s APT Attacks (AppleSeed, PebbleDash)
-
Kimsuky Group's APT Attacks (AppleSeed, PebbleDash)
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Kimsuky Group's APT Attacks (AppleSeed, PebbleDash)
-
Konni_targeting_Russian_diplomatic_sector
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Konni_targeting_Russian_diplomatic_sector
-
APT Attack Cases of Kimsuky Group (PebbleDash)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Attack Cases of Kimsuky Group (PebbleDash)
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor It is suspected that the APT-C-55 organization used the commercial software Web Browser Password Viewer to carry out the attack
-
Triple Threat- North Korea-Aligned TA406 Scams, Spies, and Steals
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Triple Threat- North Korea-Aligned TA406 Scams, Spies, and Steals
-
2021 Fall/Winter Threat Update
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2021 Fall/Winter Threat Update
-
North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean attackers use malicious blogs to deliver malware to high-profile South Korean targets
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
-
VNC Malware (TinyNuke, TightVNC) Used by Kimsuky Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor VNC Malware (TinyNuke, TightVNC) Used by Kimsuky Group
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
Operation Newton- Hi Kimsuky- Did an Apple(seed) really fall on Newton’s head-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Newton- Hi Kimsuky- Did an Apple(seed) really fall on Newton’s head-
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
North Korean Cyberattacks A Dangerous and Evolving Threat 2
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor North Korean Cyberattacks A Dangerous and Evolving Threat 2
-
Attacks using metasploit meterpreter
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attacks using metasploit meterpreter
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky Espionage Campaign
-
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Kimsuky Espionage Campaign
-
Summary of Kimsuky's secret stealing activities in the first half of 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Summary of Kimsuky's secret stealing activities in the first half of 2021
-
APT attack (by Kimsuky) attempt on a specific person using a word document
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT attack (by Kimsuky) attempt on a specific person using a word document
-
Old trees and new flowers- Analysis of the new version of KGH spy components used by Kimsuky
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Old trees and new flowers- Analysis of the new version of KGH spy components used by Kimsuky
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Dissemination of malicious word documents for 'Korean Political Science and Diplomacy' and 'Biography of Policy Advisor' (kimsuky)
-
Kimsuky APT organization's targeted attacks on South Korean defense and security related departments
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky APT organization's targeted attacks on South Korean defense and security related departments
-
Cloud Atlas Navigates Us Into New Waters
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cloud Atlas Navigates Us Into New Waters
-
Kimsuky APT continues to target South Korean government using AppleSeed backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky APT continues to target South Korean government using AppleSeed backdoor
-
APT_trends_report_Q1_2021_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q1_2021_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q1 2021
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
대북관련 본문 내용의 External 링크를 이용한 악성 워드 문서
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 대북관련 본문 내용의 External 링크를 이용한 악성 워드 문서
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analysis of the attack activity organized by Konni APT using the topic of North Korean epidemic materials as bait
-
filedownload.do?attach_file_seq=2652&attach_file_id=EpF2652.pdf
The original link failed its last check. Original publisher Detailsfor filedownload.do?attach_file_seq=2652&attach_file_id=EpF2652.pdf
-
Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2020-2021_en
-
Extrapolating Adversary Intent Through Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Extrapolating Adversary Intent Through Infrastructure
-
The many personalities of Lazarus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The many personalities of Lazarus
-
Alert (AA20-301A)- North Korean Advanced Persistent Threat Focus- Kimsuky
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Alert (AA20-301A)- North Korean Advanced Persistent Threat Focus- Kimsuky
-
TLP-WHITE_AA20-301A_North_Korean_APT_Focus_Kimsuky
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TLP-WHITE_AA20-301A_North_Korean_APT_Focus_Kimsuky
-
FY20 Microsoft Digital Defense Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor FY20 Microsoft Digital Defense Report
-
Kimsuky Phishing Operations Putting In Work
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky Phishing Operations Putting In Work
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_Threat_Report_Q22020
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 0628-2020APT上半年报告-画册
-
Probable Sandworm Infrastructure
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Probable Sandworm Infrastructure
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ASEC_REPORT_vol.98_ENG
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
Kimsuky group- tracking the king of the spear phishing
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Kimsuky group- tracking the king of the spear phishing
-
Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
-
Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 2
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
The North Korean Kimsuky APT keeps threatening South Korea evolving its TTPs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The North Korean Kimsuky APT keeps threatening South Korea evolving its TTPs
-
Lexfo-WhitePaper-The_Lazarus_Constellation
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lexfo-WhitePaper-The_Lazarus_Constellation
-
Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking ‘Kimsuky’, the North Korea-based cyber espionage group- Part 1
-
The original link failed its last check. Original publisher Detailsfor Cyber Security Services
-
2020.02.22_APT_threat_report_2019_CN_version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2020.02.22_APT_threat_report_2019_CN_version
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020_en
-
Group-IB_Hi-Tech_Crime_Trends_2019-2020
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Group-IB_Hi-Tech_Crime_Trends_2019-2020
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Autumn Aperture Report
-
Konni APT organization emerges as an attack disguised as Russian document
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Konni APT organization emerges as an attack disguised as Russian document
-
[Analysis_Report]Operation%20Kabar%20Cobra%20(1).pdf
The original link failed its last check. Original publisher Detailsfor [Analysis_Report]Operation%20Kabar%20Cobra%20(1).pdf
-
[Analysis_Report]Operation%20Kabar%20Cobra.pdf
The original link failed its last check. Original publisher Detailsfor [Analysis_Report]Operation%20Kabar%20Cobra.pdf
-
%5bAnalysis_Report%5dOperation_Kabar_Cobra.pdf
The original link failed its last check. Original publisher Detailsfor %5bAnalysis_Report%5dOperation_Kabar_Cobra.pdf
-
STOLEN PENCIL Campaign Targets Academia
The original link failed its last check. Original publisher Detailsfor STOLEN PENCIL Campaign Targets Academia
-
Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Profiling An Enigma: The Mystery Of North Korea's Cyber Threat Landscape
-
The "Kimsuky" Operation: A North Korean APT?
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The "Kimsuky" Operation: A North Korean APT?
-
The “Kimsuky” Operation- A North Korean APT-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The “Kimsuky” Operation- A North Korean APT-
-
“Red October” – Part Two, the Modules
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor “Red October” – Part Two, the Modules
Newest first. Details opens the report in Explore.