APT PROFILE – APT43
2025-02-12 • Cyfirma •
CYFIRMA profiles APT43 as a North Korean state-sponsored operator linked to the Reconnaissance General Bureau and associated with aliases including Kimsuky, Emerald Sleet, TA427, Thallium, and Velvet Chollima. The profile emphasizes strategic intelligence collection and financially motivated activity using credential harvesting, exploitation of vulnerabilities, and social engineering. It lists malware and tooling such as RftRAT, VENOMBITE, DEEP#GOSU, BITTERSWEET, SmallTiger, TinyNuke, AppleSeed, Amadey, SWEETDROP, and SuperBear, with targeting across South Korea, the United States, Japan, China, and NATO-linked European countries.
Related Actors
Related Reports
2024-09-12 •
54% Match
#Kimsuky
#T1102.002
#T1082
#T1059.003
#T1567.002
#T1140
#T1005
#T1070.004
#T1587.001
#T1041
#T1608.001
#T1071.001
#T1112
#T1083
#T1056.001
#T1059.006
#T1204.001
#T1059.007
#T1036
#T1027
#T1204.002
#T1566.002
#T1555.003
#T1057
#T1059.005
#T1583.006
#T1518.001
#T1566.001
#T1547.001
#T1585.002
#T1053.005
#T1598.003
#T1583.001
#T1059.001
#T1036.005
#T1552.001
#T1585.001
#T1105
#T1219
#T1055
#T1553.002
#T1562.001
#T1027.002
#T1133
#T1190
#T1098
#T1016
#T1074.001
#T1588.002
#T1055.012
#T1587
#T1078.003
#T1071.002
#T1562.004
#T1550.002
#T1111
#T1071.003
#T1591
#T1003.001
#T1218.011
#T1593.002
#T1586.002
#T1588.005
#T1583.004
#T1036.004
#T1589.003
#T1594
#T1218.010
#T1557
#T1593.001
#T1218.005
#T1589.002
#T1584.001
#T1070.006
#T1021.001
#T1560.001
#T1176
#T1136.001
#T1543.003
#T1012
#T1534
#T1560.003
#T1007
#T1564.003
#T1114.003
#T1114.002
#T1564.002
#T1040
#T1546.001
#T1505.003
Shares tags: T1102.002, T1082, T1059.003 • Same author: Cyfirma
Shares tag: APT43 • Published within a week
Shares tag: APT43 • Published within a month
2026-01-13 •
36% Match
#Kimsuky
#T1102.002
#T1059.003
#T1567.002
#T1070.004
#T1587.001
#T1041
#T1608.001
#T1071.001
#T1112
#T1056.001
#T1059.006
#T1204.001
#T1059.007
#T1027
#T1204.002
#T1566.002
#T1555.003
#T1059.005
#T1583.006
#T1566.001
#T1585.002
#T1053.005
#T1598.003
#T1583.001
#T1059.001
#T1036.005
#T1566
#T1585.001
#T1656
#T1205
#T1105
#T1055
#T1553.002
#T1620
#T1102.001
#T1027.002
#T1133
#T1190
#T1593
#T1588.002
#T1657
#T1055.012
#T1587
#T1078.003
#T1071.002
#T1562.004
#T1550.002
#T1111
#T1071.003
#T1591
#T1003.001
#T1218.011
#T1585
#T1593.002
#T1598
#T1583
#T1586.002
#T1588.005
#T1583.004
#T1036.004
#T1588.003
#T1589.003
#T1594
#T1218.010
#T1557
#T1219.002
#T1593.001
#T1218.005
#T1589.002
#T1584.001
#T1070.006
#T1596
Shares tags: T1102.002, T1059.003, T1567.002 • Same author: Cyfirma
2025-08-13 •
33% Match
#Lazarus
#T1102.002
#T1082
#T1059.003
#T1567.002
#T1140
#T1584.004
#T1005
#T1070.004
#T1587.001
#T1041
#T1560
#T1608.001
#T1071.001
#T1046
#T1083
#T1056.001
#T1204.001
#T1036
#T1027
#T1204.002
#T1566.002
#T1566.003
#T1124
#T1057
#T1059.005
#T1583.006
#T1566.001
#T1547.001
#T1585.002
#T1053.005
#T1583.001
#T1059.001
#T1036.005
#T1132.001
#T1001.003
#T1585.001
#T1497.001
#T1105
#T1553.002
#T1620
#T1574.002
#T1562.001
#T1027.002
#T1489
#T1078
#T1008
#T1571
#T1491.001
#T1218
#T1220
#T1203
#T1189
#T1049
#T1564.001
#T1098
#T1016
#T1074.001
#T1588.002
#T1562.004
#T1591
#T1218.011
#T1583.004
#T1036.004
#T1588.003
#T1218.010
#T1593.001
#T1218.005
#T1589.002
#T1584.001
#T1070.006
#T1048.003
#T1134.002
#T1027.007
#T1021.001
#T1106
#T1090.001
#T1573
#T1070
#T1047
#T1574.013
#T1561.001
#T1036.003
#T1529
#T1055.001
#T1614.001
#T1010
#T1021.002
#T1033
#T1543.003
#T1485
#T1090.002
#T1542.003
#T1560.002
#T1012
#T1110
#T1547.009
#T1110.003
#T1534
#T1588.004
#T1104
#T1591.004
#T1561.002
#T1608.002
#T1202
#T1221
#T1557.001
#T1087.002
#T1560.003
#T1070.003
#T1021.004
Shares tags: T1102.002, T1082, T1059.003 • Same author: Cyfirma
2025-02-20 •
30% Match
#BeaverTail
#InvisibleFerret
#DeceptiveDevelopment
#T1027.013
#T1082
#T1119
#T1059.003
#T1140
#T1005
#T1587.001
#T1041
#T1608.001
#T1071.001
#T1115
#T1083
#T1056.001
#T1059.006
#T1059.007
#T1204.002
#T1566.003
#T1555.003
#T1124
#T1583.003
#T1552.001
#T1585.001
#T1219
#T1133
#T1571
#T1564.001
#T1016
#T1074.001
#T1657
#T1071.002
#T1021.001
#T1614
#T1555.001
#T1217
#T1095
#T1025
#T1010
#T1560.002
#T1030
#T1567.004
#T1564.003
Shares tags: T1082, T1059.003, T1140 • Published within a month