Threat Actor ๐Ÿ‡ฐ๐Ÿ‡ต North Korea

Kimsuky

Also known as: Velvet Chollima ยท Black Banshee ยท Thallium ยท Operation Stolen Pencil ยท G0086 ยท APT43 ยท Emerald Sleet ยท THALLIUM ยท Springtail ยท Sparkling Pisces

This threat actor targets South Korean think tanks, industry, nuclear power operators, and the Ministry of Unification for espionage purposes.

Indicators of Compromise 13

MITRE ATT&CK TTPs 8

Source Articles

Critical ScreenConnect flaw now actively exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a critical-severity vulnerability in ConnectWise ScreenConnect, tracked as CVE-2026-84869. The flaw, which stems from improper privilege management and missing authorization, allows attackers with basic privileges to transfer or execute files during active remote sessions without requiring user interaction. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog and mandated federal agencies to remediate it within three days. Over 1,000 unpatched instances remain exposed globally, primarily in North America and Europe, posing significant risks to federal and enterprise networks.
bleeping-computer ยท1w ago
ConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has identified a vulnerability in its ScreenConnect remote access platform that affects both cloud and on-premises deployments, specifically related to insecure file transfer behavior. A CVE ID has not yet been assigned, and no patch is currently available, though temporary mitigations are recommended. The vulnerability could allow attackers to abuse file transfer permissions during sessions, posing a risk to managed service providers and IT support teams. Given the history of exploitation of ScreenConnect flaws by ransomware groups and state-backed actors, this issue is considered high risk.
bleeping-computer ยท2w ago
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux backdoor named 'ted' has been discovered embedded within trojanized HAProxy binaries deployed at two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, enables command-and-control (C2) communication by mimicking legitimate HTTP responses, and allows attackers to execute shell commands, upload/download files, and modify configurations. Rapid7 Labs attributes the activity with medium confidence to North Korean state-sponsored actors, potentially linked to APT37, Lazarus, and Kimsuky clusters, based on infrastructure overlaps and operational patterns. The backdoor evades logging by manipulating HAProxy's internal connection counters and uses trojanized system binaries such as crond, sshd, agetty, atd, and polkitd to maintain persistence and exfiltrate credentials.
hacker-news ยท2w ago
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
Kimsuky, a North Korean state-sponsored threat actor, is building an offline AI stack to enhance its phishing operations and automate malware development. The group has been observed deploying tools like Ollama, GPT4All, and Msty on its own infrastructure, with evidence of configured local document databases (localdocs_v3.db) indicating use of retrieval-augmented generation (RAG) for intelligence analysis. Additional tools such as LLaMaSharp, Microsoft Semantic Kernel, Whisper, and Cursor suggest efforts to integrate AI into custom malware development and speech-to-text processing. This activity supports the ongoing Operation GitPower, which abuses GitHub repositories as command-and-control channels and delivers AsyncRAT payloads.
hacker-news ยท1mo ago