#APT43
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
February 14, 2025 at 3:45 AM
APT43 activity with multiple European embassies being spoofed and likely targeted. Rapport building themes and lures center around DPRK Human Rights and reactions to DPRKs official stance on NK troops in Russia cc @jennytown.bsky.social @elias.foxhold.net @garyfreasbysm.bsky.social
May 9, 2025 at 6:16 PM
Extensive analysis of PHRACK's "North Korea Files"🇰🇵
dti.domaintools.com/inside-the-k...
🔥
* “the most comprehensive and technically intimate disclosures”
* “a smoking gun”
* "clear evidence ... infiltrate the nation’s digital trust infrastructure at multiple levels”
* “far beyond phishing”
Inside the Kimsuky Leak: How the “Kim” Dump Exposed North Korea’s Credential Theft Playbook - DomainTools Investigations | DTI
A rare and revealing breach attributed to a North Korean-affiliated actor, known only as “Kim” as named by the hackers who dumped the data, has delivered a new insight into Kimsuky (APT43) tactics, te...
dti.domaintools.com
September 6, 2025 at 1:06 PM
APT43 Hackers Attacking Academic Institutions With Exposed Credentials
APT43 Hackers Attacking Academic Institutions With Exposed Credentials
cybersecuritynews.com
February 14, 2025 at 8:04 AM
North Korea's APT43 targets academics globally, stealing crypto and data via malware (RftRAT, VENOMBITE, DEEP#GOSU). They use reconnaissance, execution, and evasion tactics. Robust credential security & updated protocols are vital.#APT43Threat
February 14, 2025 at 5:21 AM
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks
thehackernews.com
February 13, 2025 at 2:53 PM
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks thehackernews.com/2025/02/nort...
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks
North Korean APT43 exploits PowerShell and Dropbox in a multi-stage attack on South Korean sectors.
thehackernews.com
February 16, 2025 at 2:34 PM
North Korean hackers (APT37/ScarCruft) spread Android spyware "KoSpy" via Google Play disguised as utility apps. Stealing data (SMS, calls, location) from March 2022, Google removed it. Targeting Korean & English speakers, it used Firebase. APT43 may have also used KoSpy.#KoSpySpyware
March 14, 2025 at 4:05 AM
Your #SOC isn’t daycare. Drop #APT43 into AlphaHunt Chat and watch the AI spit out pivots like “Which IOCs?”, “What defenses?”, “Where’s the geo-political fire?”—no more training younglings, just crushing threats. Join us ➡️ alphahunt.io

#AlphaHunt #CyberSecurity #ThreatIntel
June 27, 2025 at 4:52 PM
DomainTools analyses the “Kim” dump, revealing Kimsuky (APT43) tactics and layered infrastructure. Contents include bash histories, OCR workflows, phishing domains, compiled stagers, and a Linux rootkit, with activity targeting South Korea and Taiwan. dti.domaintools.com/inside-the-k...
September 8, 2025 at 8:38 AM
NSA warns of North Korean hackers exploiting weak DMARC email policies
NSA warns of North Korean hackers exploiting weak DMARC email policies
The NSA and FBI warned that the APT43 North Korea-linked hacking group exploits weak email Domain-based Message Authentication Reporting and Conformance (DMARC) policies to mask spearphishing attacks.
www.bleepingcomputer.com
May 3, 2024 at 7:22 PM
The group — APT43 — has been operating since at least 2012, according to U.S. government estimates, and works under the umbrella of North Korea’s Reconnaissance General Bureau (RGB), the country’s primary intelligence service.
cyberscoop.com/u-s-governme...
U.S. government sanctions prolific North Korean cyber espionage unit
The veteran hacking crew has been at the heart of Pyongyang's efforts to gather intelligence by breaching computer systems.
cyberscoop.com
December 1, 2023 at 8:43 PM
📌 Legendary Hackers Expose Kimsuky Member's Compromise in Phrack Magazine https://www.cyberhub.blog/article/11639-legendary-hackers-expose-kimsuky-members-compromise-in-phrack-magazine
Legendary Hackers Expose Kimsuky Member's Compromise in Phrack Magazine
In a notable development, hackers known as Saber and cyb0rg have published an article in the latest issue of Phrack magazine, detailing their successful compromise of a member belonging to the North Korean espionage hacking group Kimsuky, also identified as APT43 and Thallium. Phrack, a venerable e-zine with roots tracing back to 1985, serves as a platform for high-profile disclosures within the hacking community. While the article does not divulge specific technical details or concrete impacts of the hack, the revelation carries significant implications for the cybersecurity landscape. The compromise of a Kimsuky member underscores the vulnerability of even sophisticated advanced persistent threat (APT) groups to operational security failures. Kimsuky, a group known for its cyber espionage activities targeting government entities and think tanks, is typically associated with stringent security measures. The breach suggests potential lapses in their operational security (OPSEC), which could have been exploited by Saber and cyb0rg. Such incidents highlight the perpetual cat-and-mouse game in cybersecurity, where even well-resourced and skilled groups are not immune to breaches. The publication in Phrack adds a layer of credibility and visibility to the disclosure. Historically, Phrack has been a platform for sharing in-depth technical knowledge and hacking methodologies. Although the current article lacks specific technical details, the fact that it was published in Phrack suggests that the hackers may have shared insights into Kimsuky's operations or methodologies, albeit at a high level. This could provide valuable intelligence to cybersecurity defenders and other threat actors, potentially leading to shifts in Kimsuky's tactics, techniques, and procedures (TTPs) as they adapt to the exposure. From a broader cybersecurity perspective, this incident serves as a reminder of the importance of maintaining robust OPSEC practices. For organizations defending against APT groups like Kimsuky, this event could offer an opportunity to glean insights into the group's operations, should more details emerge. It also underscores the value of threat intelligence sharing within the cybersecurity community. However, the lack of specific technical details in the article limits the immediate actionable intelligence that can be derived from this disclosure. Cybersecurity professionals should monitor for any additional information that may surface, particularly regarding the methods used by Saber and cyb0rg to compromise the Kimsuky member. Such details could provide critical insights into defending against similar attacks or understanding potential vulnerabilities within APT groups. In conclusion, while the full impact of this breach remains unclear due to the lack of technical specifics, the event itself is noteworthy. It highlights the ongoing risks and challenges in cybersecurity, even for advanced threat actors. The cybersecurity community should remain vigilant for further developments and potential shifts in Kimsuky's TTPs as a result of this exposure.
www.cyberhub.blog
August 14, 2025 at 4:00 AM
Kimsuky APT group used custom RDP Wrapper version and forceCopy stealer

Researchers spotted North Korea’s Kimsuky APT group launching spear-phishing attacks to deliver forceCopy info-stealer malware. Researchers from AhnLab Security Intelligence Center (ASEC) observed North Kore…

#hackernews #news
Kimsuky APT group used custom RDP Wrapper version and forceCopy stealer
Researchers spotted North Korea’s Kimsuky APT group launching spear-phishing attacks to deliver forceCopy info-stealer malware. Researchers from AhnLab Security Intelligence Center (ASEC) observed North Korea’s Kimsuky APT group conducting spear-phishing attacks to deliver forceCopy info-stealer malware. Kimsuky cyberespionage group (aka ARCHIPELAGO, Black Banshee, Thallium, Velvet Chollima, APT43) was first spotted by Kaspersky researchers in 2013. The group works under the control […]
securityaffairs.com
February 10, 2025 at 3:27 AM
GitHubを悪用する北朝鮮のサイバー攻撃、中国関与の可能性も - マイナビニュース

GitHub悪用によるKimsukyのスパイ活動全容. 攻撃者はGitHubを指令・制御チャネルとして悪用し、DropboxやDaumといったクラウドストレージを通じてマルウェアを
news.mynavi.jp/techplus/art...
GitHubを悪用する北朝鮮のサイバー攻撃、中国関与の可能性も
Trellixは8月18日(米国時間)、北朝鮮のサイバー部隊Kimsuky(APT43)が主導するスパイ活動について明らかにした。彼らは2025年3月から7月にかけて、ソウルの複数大使館を狙い、外交官になりすましたスピアフィッシングを展開。GitHubやクラウドストレージを悪用し、XenoRATを用いた高度な遠隔操作を実施した。
news.mynavi.jp
August 22, 2025 at 11:53 PM
キムスクの新キャンペーンが韓国のソフトウェアベンダーを脅迫

北朝鮮のハッカーが韓国の共同作​​業ソフトウェアベンダーを標的にし、その後、サプライヤーの顧客に侵入することに成功したことが、脅威研究者によって明らかになった。

APT43としても知られるキムスクグループによるこの攻撃は、2025年から2026年初頭にかけて行われた。同グループは過去に、韓国企業の企業インフラや政府機関を標的にしてきた。

韓国のサイバーセキュリティ企業ENKI WhiteHatの研究者が観察した事例の一つでは、ハッカーはリモートコード実行の脆弱性を悪用してマルウェアをインストールすることで、外部からア...
New Kimsuky campaign compromised South Korean software vendors
A North Korean advanced persistent threat (APT) group recently targeted vendors of collaborative-work software, South Korean researchers said.
therecord.media
August 22, 2026 at 1:10 AM