All threat actors

Kimsuky

Alert me

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group linked to North Korea, with known aliases including APT43 and Black Banshee. The group has targeted South Korean government agencies, think tanks, and U.S. organizations focused on Korean Peninsula issues, as well as entities in government, education, and business sectors across multiple countries. Kimsuky has used spear phishing and social engineering tactics, often employing spoofed identities, and has been associated with malware families such as gh0st RAT and COINTOSS. The group has also been observed using commercial large language models for vulnerability research and reconnaissance.

Also known as

APT43
Black Banshee
Earth Kumiho
Emerald Sleet
PatheticSlug
Springtail
TA427
THALLIUM
Velvet Chollima

Create a free account to see the reports

Sign in or create a free account to see every report that names Kimsuky.

Create free account