Kimsuky
2019-08-26 • MITRE •
The MITRE ATT&CK entry catalogs Kimsuky, also tracked as APT43, THALLIUM, Emerald Sleet, and related aliases, with techniques spanning infrastructure acquisition, credential theft, exfiltration, and persistence. The group has registered spoofed domains, used Blogspot and Dropbox for targeting or payload hosting, and leveraged HTTP, FTP, and email for command-and-control or data movement. Documented behaviors include archiving stolen files, RC4 encryption before exfiltration, scheduled exfiltration checks, and abuse of local or domain groups. The page provides a technique-focused reference for defenders mapping Kimsuky activity to ATT&CK detections.