Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0094
MITRE ATT&CK Group

Kimsuky (G0094)

Black BansheeVelvet ChollimaEmerald SleetTHALLIUMAPT43TA427SpringtailEarth KumihoPatheticSlug
ShareXLinkedInRedditHN

[Kimsuky](https://attack.mitre.org/groups/G0094) is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. [Kimsuky](https://attack.mitre.org/groups/G0094) has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. [Kimsuky](https://attack.mitre.org/groups/G0094) operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing.(Citation: EST Kimsuky April 2019)(Citation: Cybereason Kimsuky November 2020)(Citation: Malwarebytes Kimsuky June 2021)(Citation: CISA AA20-301A Kimsuky)(Citation: Mandiant APT43 March 2024)(Citation: Proofpoint TA427 April 2024) [Kimsuky](https://attack.mitre.org/groups/G0094) was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019).(Citation: Netscout Stolen Pencil Dec 2018)(Citation: EST Kimsuky SmokeScreen April 2019)(Citation: AhnLab Kimsuky Kabar Cobra Feb 2019) In 2023, [Kimsuky](https://attack.mitre.org/groups/G0094) was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance.(Citation: MSFT-AI) DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under [Lazarus Group](https://attack.mitre.org/groups/G0032), rather than tracking operationally distinct subgroups.

▪Techniques used (131)

T1678Delay ExecutionT1005Data from Local SystemT1587.001MalwareT1583Acquire InfrastructureT1021.001Remote Desktop ProtocolT1585.002Email AccountsT1566PhishingT1685Disable or Modify ToolsT1204.002Malicious FileT1040Network SniffingT1566.002Spearphishing LinkT1056.003Web Portal CaptureT1539Steal Web Session CookieT1588.002ToolT1078.003Local AccountsT1020Automated ExfiltrationT1140Deobfuscate/Decode Files or InformationT1204.004Malicious Copy and PasteT1027.010Command ObfuscationT1608.001Upload MalwareT1105Ingress Tool TransferT1587Develop CapabilitiesT1567.002Exfiltration to Cloud StorageT1598Phishing for InformationT1684.001ImpersonationT1553.002Code SigningT1036.004Masquerade Task or ServiceT1115Clipboard DataT1559.001Component Object ModelT1102.002Bidirectional CommunicationT1489Service StopT1217Browser Information DiscoveryT1204.001Malicious LinkT1534Internal SpearphishingT1190Exploit Public-Facing ApplicationT1593.001Social MediaT1027.007Dynamic API ResolutionT1027.013Encrypted/Encoded FileT1585Establish AccountsT1589.003Employee NamesT1218.011Rundll32T1564.002Hidden UsersT1176.001Browser ExtensionsT1070.004File DeletionT1219.002Remote Desktop SoftwareT1583.004ServerT1552.004Private KeysT1620Reflective Code LoadingT1111Multi-Factor Authentication InterceptionT1594Search Victim-Owned WebsitesT1059.003Windows Command ShellT1583.001DomainsT1012Query RegistryT1591Gather Victim Org InformationT1071.001Web ProtocolsT1585.001Social Media AccountsT1657Financial TheftT1136.001Local AccountT1007System Service DiscoveryT1568Dynamic ResolutionT1027.001Binary PaddingT1586.002Email AccountsT1560.003Archive via Custom MethodT1070.006TimestompT1598.003Spearphishing LinkT1027.012LNK Icon SmugglingT1596Search Open Technical DatabasesT1027.016Junk Code InsertionT1550.002Pass the HashT1557Adversary-in-the-MiddleT1518.001Security Software DiscoveryT1218.005MshtaT1041Exfiltration Over C2 ChannelT1185Browser Session HijackingT1564.011Ignore Process InterruptsT1686Disable or Modify System FirewallT1133External Remote ServicesT1082System Information DiscoveryT1106Native APIT1584.001DomainsT1589.002Email AddressesT1059.007JavaScriptT1497.001System ChecksT1027Obfuscated Files or InformationT1074.001Local Data StagingT1071.003Mail ProtocolsT1056.001KeyloggingT1027.002Software PackingT1552.001Credentials In FilesT1102.001Dead Drop ResolverT1560.001Archive via UtilityT1016System Network Configuration DiscoveryT1555.003Credentials from Web BrowsersT1055.001Dynamic-link Library InjectionT1546.001Change Default File AssociationT1566.001Spearphishing AttachmentT1057Process DiscoveryT1055Process InjectionT1113Screen CaptureT1112Modify RegistryT1059.001PowerShellT1588.005ExploitsT1218.010Regsvr32T1547.001Registry Run Keys / Startup FolderT1543.003Windows ServiceT1583.006Web ServicesT1682Query Public AI ServicesT1083File and Directory DiscoveryT1564.003Hidden WindowT1027.015CompressionT1053.005Scheduled TaskT1033System Owner/User DiscoveryT1480.002Mutual ExclusionT1036.005Match Legitimate Resource Name or LocationT1132.002Non-Standard EncodingT1593.002Search EnginesT1036.007Double File ExtensionT1055.012Process HollowingT1588.003Code Signing CertificatesT1114.003Email Forwarding RuleT1071.002File Transfer ProtocolsT1003.001LSASS MemoryT1205Traffic SignalingT1059.005Visual BasicT1098.007Additional Local or Domain GroupsT1059.006PythonT1505.003Web ShellT1680Local Storage DiscoveryT1114.002Remote Email CollectionT1124System Time DiscoveryT1660Phishing

▪Software used (19)

S1196Troll StealermalwareS9007HTTPTroymalwareS0111schtaskstoolS0160certutiltoolS1025AmadeymalwareS1197GoBearmalwareS0252Brave PrincemalwareS0527CSPY DownloadertoolS0032gh0st RATmalwareS0622AppleSeedmalwareS1198GomirmalwareS0353NOKKImalwareS0262QuasarRATtoolS0249Gold DragonmalwareS0029PsExectoolS0526KGH_SPYmalwareS0002MimikatztoolS0414BabySharkmalwareS1201TRANSLATEXTmalware
G0094on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.