Kimsuky APT Group - Key Insights for UK Energy CISOs

2023-03-28 Bridewell

https://www.bridewell.com/insights/news/detail/bridewell-intelligence-report-kimsuky-apt-group---key-insights-for-uk-energy-cisos

Thumbnail for Kimsuky APT Group - Key Insights for UK Energy CISOs

Kimsuky employs a range of tactics, techniques, and procedures (TTPs) such as spear-phishing campaigns, social engineering, and custom malware to compromise its targets and exfiltrate sensitive data. Strengthen security awareness training for employees, emphasising the importance of vigilance against spear-phishing campaigns and social engineering tactics often used by Kimsuky. Recently, we reviewed the joint cyber security advisory published on March 20th, 2023 by the German domestic intelligence agency, Bundesamt für Verfassungsschutz (BfV), and the South Korean National Intelligence Service (NIS) on the North Korean Advanced Persistent Threat (APT) group, Kimsuky. Kimsuky, also known as Velvet Chollima, Thallium, and Black Banshee, is a North Korean APT group that has been active since at least 2012.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 92.38.160.4 2023-03-28 2023-03-28
IPv4 92.38.160.161 2023-03-28 2023-03-28
IPv4 92.38.160.10 2023-03-28 2023-03-28
IPv4 92.38.160.44 2023-03-28 2023-03-28
IPv4 92.38.135.136 2023-03-28 2023-03-28
IPv4 220.123.200.183 2023-03-28 2023-03-28
IPv4 92.38.160.84 2023-03-28 2023-03-28
IPv4 92.38.160.23 2023-03-28 2023-03-28
IPv4 92.38.135.159 2023-03-28 2023-03-28
IPv4 209.127.36.73 2023-03-28 2023-03-28
IPv4 92.38.160.155 2023-03-28 2023-03-28
IPv4 92.38.160.140 2023-03-28 2023-03-28
IPv4 92.38.160.43 2023-03-28 2023-03-28
IPv4 220.84.114.158 2023-03-28 2023-03-28
IPv4 92.38.160.131 2023-03-28 2023-03-28
IPv4 92.38.160.81 2023-03-28 2023-03-28
IPv4 61.253.107.35 2023-03-28 2023-03-28
IPv4 58.229.169.224 2023-03-28 2023-03-28
IPv4 92.38.135.166 2023-03-28 2023-03-28
IPv4 92.38.135.148 2023-03-28 2023-03-28
IPv4 92.38.135.195 2023-03-28 2023-03-28
IPv4 45.114.129.146 2023-03-28 2023-03-28
IPv4 92.38.160.172 2023-03-28 2023-03-28
IPv4 92.38.135.213 2022-11-23 2023-03-28

Related Actors

Related Reports

« Back