Activity timeline
APT43 appears in 15 tracked threats between and ; the busiest month was 2026-07 with 5 reports.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 12 of 15 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 12 of 15 tracked threats
- T1082 System Information Discovery — Discoveryobserved in 12 of 15 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 12 of 15 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 11 of 15 tracked threats
- T1005 Data from Local System — Collectionobserved in 8 of 15 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 8 of 15 tracked threats
- T1071.001 Web Protocols — Command and Controlobserved in 8 of 15 tracked threats
- T1057 Process Discovery — Discoveryobserved in 7 of 15 tracked threats
- T1566 Phishing — Initial Accessobserved in 7 of 15 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 6 of 15 tracked threats
- T1056.001 Keylogging — Credential Accessobserved in 6 of 15 tracked threats
- T1059.001 PowerShell — Executionobserved in 6 of 15 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 6 of 15 tracked threats
- T1083 File and Directory Discovery — Discoveryobserved in 6 of 15 tracked threats
Tracked threats
- Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage CampaignHIGH
- Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)HIGH
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS CustomerHIGH
- ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain CompromiseMEDIUM
- Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected KimsukyHIGH
- ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion TechniquesHIGH
- macOS.Gaslight - Rust Backdoor with AI-Analysis Evasion & Prompt InjectionCRITICAL
- Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead ListsHIGH
- DPRK (Kimsuky) Multi-Stage LNK Phishing Campaign Delivering XenoRAT via GitHub-based C2 Targeting South KoreaHIGH
- Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote Tunnel Abuse Against South KoreaHIGH
- ASEC April 2026 APT Trend Report (South Korea) — Kimsuky-Aligned LNK/PowerShell/AutoIt Spear-Phishing with PubNub C2, GitHub-Hosted HTA & XenoRAT (5 Infection Types)HIGH
- Kimsuky CHM Dropper / VBScript Stager / PowerShell Keylogger Kill Chain Recovered from Live C2 (api_reference.chm, check.nid-log.com)HIGH
- Screensaver (.SCR) Files Used as Initial Access VectorHIGH
- eScan Antivirus Supply Chain Attack - Update Server CompromiseCRITICAL
- GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain Attack Hijacking eScan Antivirus HTTP Updates via AitMCRITICAL