APT PROFILE – KIMSUKY
2024-09-12 • Cyfirma •
CYFIRMA profiles Kimsuky as a North Korean hacking group active since at least 2018 and engaged in espionage and financially motivated cybercrime aligned with North Korean state interests. The profile lists target exposure across South Korea, the United States, Japan, Vietnam, and European countries with NATO ties, and notes affected technology areas including office suites, operating systems, and web applications. The excerpt maps Kimsuky activity to vulnerabilities such as CVE-2024-21338, CVE-2021-44228, CVE-2017-11882, CVE-2017-0199, and others. It also provides a broad MITRE ATT&CK matrix spanning reconnaissance, resource development, initial access, execution, persistence, defense evasion, discovery, collection, credential access, command and control, exfiltration, lateral movement, and privilege escalation. The mapped techniques include phishing, scheduled tasks, PowerShell and command-shell execution, obfuscation, credential dumping, web services for C2, ingress tool transfer, and cloud exfiltration paths.