Overview
Kimsuky (MITRE ATT&CK ID G0094) is a Democratic People’s Republic of Korea (DPRK)-based cyber espionage group MITRE ATT&CK documents as active since at least 2012. Per MITRE’s group profile, Kimsuky initially targeted South Korean government agencies, think tanks, and subject-matter experts before expanding operations to the United Nations and organizations in government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. MITRE’s synthesis (itself citing prior vendor reporting from ESTsecurity, Cybereason, Malwarebytes, CISA, Mandiant, and Proofpoint) describes the group’s collection focus as foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions.
Notably, MITRE’s data records that Kimsuky was observed in 2023 using commercial large language models to assist with vulnerability research, scripting, social engineering, and reconnaissance — one of the more concrete documented instances of an APT group’s LLM usage in the ATT&CK knowledge base.
Attribution caveat
MITRE ATT&CK notes that DPRK threat-actor cluster boundaries overlap significantly in open-source reporting, with some security researchers consolidating all North Korean state-sponsored cyber activity under Lazarus Group rather than tracking Kimsuky as an operationally distinct subgroup. Treat “Kimsuky” as the security research community’s working designation, not a confirmed, cleanly bounded organizational unit.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested MITRE ATT&CK data links Kimsuky to malware including AppleSeed, BabyShark, Gold Dragon, Gomir, GoBear, Troll Stealer, HTTPTroy, KGH_SPY, QuasarRAT, gh0st RAT, NOKKI, and Brave Prince, alongside dual-use tools like Mimikatz, PsExec, and certutil.
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to Kimsuky in our data include Acquire Infrastructure (T1583), Adversary-in-the-Middle (T1557), Automated Exfiltration (T1020), Bidirectional Communication (T1102.002), and Binary Padding (T1027.001), among others documented in the group’s ATT&CK profile.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups (only campaigns carry that field in our data), so we report “active since at least 2012” per MITRE’s description text rather than a precise window. We have no independent telemetry, IOC feed, or detection data beyond what MITRE’s STIX bundle documents, and no confirmation of current operational status beyond MITRE’s own synthesis of public reporting.
Frequently Asked Questions
What is Kimsuky? A DPRK-based cyber espionage group, per MITRE ATT&CK, active since at least 2012 and focused on intelligence collection tied to Korean Peninsula foreign policy and nuclear issues.
Is Kimsuky the same as Lazarus Group? Not identically — MITRE ATT&CK tracks them as separate group entries, but its own documentation notes DPRK threat-actor clusters overlap significantly in public reporting, and some researchers group all North Korean state activity under Lazarus Group instead.
What malware does Kimsuky use? Per MITRE ATT&CK’s relationship data, tools linked to Kimsuky include AppleSeed, BabyShark, Gold Dragon, Gomir, GoBear, Troll Stealer, and QuasarRAT, among others.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0094, aggregated September 9, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.