← Back to all threat actors

Kimsuky

Also known as Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug
Tracked as G0094

Kimsuky is a Democratic People's Republic of Korea (DPRK)-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter experts in various fields. Its operations expanded to include the United Nations and organizations in the government, education, business services, and manufacturing sectors across the United States, Japan, Russia, and Europe. Kimsuky has focused collection on foreign policy and national security issues tied to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky operations have overlapped with those of other North Korean state-sponsored cyber espionage actors as a result of ad hoc collaborations or other limited resource sharing. Kimsuky was assessed to be responsible for the 2014 Korea Hydro & Nuclear Power Co. compromise; other notable campaigns include Operation STOLEN PENCIL (2018), Operation Kabar Cobra (2019), and Operation Smoke Screen (2019). In 2023, Kimsuky was observed using commercial large language models (LLMs) to assist with vulnerability research, scripting, social engineering and reconnaissance. DPRK threat actor cluster boundaries overlap in open source reporting, with some security researchers consolidating all attributed North Korean state-sponsored cyber activity under Lazarus Group, rather than tracking operationally distinct subgroups.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
KP
Sectors
government, defense, research-academia
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G0094

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Black Banshee

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Velvet Chollima

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Emerald Sleet

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: THALLIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: APT43

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: TA427

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Springtail

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Earth Kumiho

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: PatheticSlug

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2017-11882 linked to this actor
Cataloged
CVECVE-2022-41040 linked to this actor
Cataloged
CVECVE-2022-41082 linked to this actor

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

KimsukyCanonical Name
APT43Alias
Black BansheeAlias
Earth KumihoAlias
Emerald SleetAlias
PatheticSlugAlias
SpringtailAlias
TA427Alias
THALLIUMAlias
Velvet ChollimaAlias
G0094Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...