Kimsuky APT Group - Key Insights for UK Energy CISOs
2023-03-28 • Bridewell •
Kimsuky employs a range of tactics, techniques, and procedures (TTPs) such as spear-phishing campaigns, social engineering, and custom malware to compromise its targets and exfiltrate sensitive data. Strengthen security awareness training for employees, emphasising the importance of vigilance against spear-phishing campaigns and social engineering tactics often used by Kimsuky. Recently, we reviewed the joint cyber security advisory published on March 20th, 2023 by the German domestic intelligence agency, Bundesamt für Verfassungsschutz (BfV), and the South Korean National Intelligence Service (NIS) on the North Korean Advanced Persistent Threat (APT) group, Kimsuky. Kimsuky, also known as Velvet Chollima, Thallium, and Black Banshee, is a North Korean APT group that has been active since at least 2012.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 92.38.160.4 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.161 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.10 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.44 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.135.136 | 2023-03-28 | 2023-03-28 |
| IPv4 | 220.123.200.183 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.84 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.23 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.135.159 | 2023-03-28 | 2023-03-28 |
| IPv4 | 209.127.36.73 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.155 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.140 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.43 | 2023-03-28 | 2023-03-28 |
| IPv4 | 220.84.114.158 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.131 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.81 | 2023-03-28 | 2023-03-28 |
| IPv4 | 61.253.107.35 | 2023-03-28 | 2023-03-28 |
| IPv4 | 58.229.169.224 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.135.166 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.135.148 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.135.195 | 2023-03-28 | 2023-03-28 |
| IPv4 | 45.114.129.146 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.160.172 | 2023-03-28 | 2023-03-28 |
| IPv4 | 92.38.135.213 | 2022-11-23 | 2023-03-28 |