Skip to content
← All Threat Actors
Nation-State North Korea (DPRK)

TA427 / Kimsuky

North Korean state-sponsored (RGB — Reconnaissance General Bureau) · Espionage — strategic intelligence collection on foreign policy, nuclear policy, sanctions, defence procurement, and AI research

Reports 1
Active Since 2012
Last Reported 20 Jul 2026
Sectors Targeted government, defence, think-tanks, energy, academia

Tactics, Techniques & Procedures (TTPs)

  • Long-duration social engineering: weeks or months building trusted personas as academics, policy researchers, journalists, or government officials before any credential phishing attempt
  • Web bug / tracking pixel deployment in initial contact emails to collect target IP, device, email client, and location before any active attack phase
  • BabyShark VBScript backdoor: long-standing primary implant for collection, file staging, and persistent access
  • Konni RAT: Windows RAT used for credential theft, file exfiltration, keylogging, and screenshot capture in targeted espionage campaigns
  • AppleSeed implant: Android mobile targeting of high-value individual assets
  • Malicious browser extensions mimicking legitimate research tools — silently exfiltrate browsing data, email content, and document access patterns
  • Use of personal email accounts (Gmail, Outlook) rather than targeting corporate endpoints — bypasses enterprise security controls entirely
  • Targeting of personal social media and messaging accounts for intelligence collection and persona maintenance

Known Targets

Nuclear policy researchers and academics (US, South Korea, Europe)Government officials and diplomats with Korean Peninsula policy remitThink tanks and foreign policy research institutesUS and European defence procurement officials (expanded from 2025)Energy sector officials with strategic infrastructure responsibilitiesAI and ML research communities (expanded targeting from 2025–2026)South Korean government and military personnel (primary historical target)

Analyst Notes

TA427/Kimsuky is North Korea's primary strategic intelligence collection operation, distinct from Lazarus Group (which focuses on financial theft) and DPRK IT Worker Networks (revenue generation). The group's defining characteristic is patience: months of persona maintenance — maintaining active Twitter/X, LinkedIn, and academic forum presence as credible research personas — before any credential phishing attempt. This approach achieves significantly higher success rates than conventional campaigns against expert targets who are otherwise resistant to obvious phishing. The targeting expansion from 2025 to include energy sector officials, defence procurement personnel, and AI research communities reflects Pyongyang's evolving intelligence requirements as sanctions pressure, energy dependency, and AI capability development all become higher priorities. CISA Advisory AA23-347A (December 2023) documented Kimsuky TTPs in detail. Web bug / tracking pixel deployment in initial benign emails to fingerprint targets before any active attack is a sophisticated pre-attack intelligence collection technique.

Also Known As

KimsukyEmerald Sleet (Microsoft)Black Banshee (CrowdStrike)Velvet ChollimaAPT43 (Mandiant)TA427 (Proofpoint)Thallium (Microsoft legacy)