TA427 / Kimsuky
North Korean state-sponsored (RGB — Reconnaissance General Bureau) · Espionage — strategic intelligence collection on foreign policy, nuclear policy, sanctions, defence procurement, and AI research
Tactics, Techniques & Procedures (TTPs)
- Long-duration social engineering: weeks or months building trusted personas as academics, policy researchers, journalists, or government officials before any credential phishing attempt
- Web bug / tracking pixel deployment in initial contact emails to collect target IP, device, email client, and location before any active attack phase
- BabyShark VBScript backdoor: long-standing primary implant for collection, file staging, and persistent access
- Konni RAT: Windows RAT used for credential theft, file exfiltration, keylogging, and screenshot capture in targeted espionage campaigns
- AppleSeed implant: Android mobile targeting of high-value individual assets
- Malicious browser extensions mimicking legitimate research tools — silently exfiltrate browsing data, email content, and document access patterns
- Use of personal email accounts (Gmail, Outlook) rather than targeting corporate endpoints — bypasses enterprise security controls entirely
- Targeting of personal social media and messaging accounts for intelligence collection and persona maintenance
Known Targets
Analyst Notes
TA427/Kimsuky is North Korea's primary strategic intelligence collection operation, distinct from Lazarus Group (which focuses on financial theft) and DPRK IT Worker Networks (revenue generation). The group's defining characteristic is patience: months of persona maintenance — maintaining active Twitter/X, LinkedIn, and academic forum presence as credible research personas — before any credential phishing attempt. This approach achieves significantly higher success rates than conventional campaigns against expert targets who are otherwise resistant to obvious phishing. The targeting expansion from 2025 to include energy sector officials, defence procurement personnel, and AI research communities reflects Pyongyang's evolving intelligence requirements as sanctions pressure, energy dependency, and AI capability development all become higher priorities. CISA Advisory AA23-347A (December 2023) documented Kimsuky TTPs in detail. Web bug / tracking pixel deployment in initial benign emails to fingerprint targets before any active attack is a sophisticated pre-attack intelligence collection technique.
Also Known As
MITRE ATT&CK Techniques