# APT43

> As of 2026-08-13, APT43 is a threat actor tracked by Threadlinqs Intelligence across 15 threats spanning apt, malware, supply chain. ATT&CK coverage spans 157 techniques across 16 tactics in 15 of 15 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1082 (System Information Discovery).

- **Tracked threats:** 15
- **Categories:** APT, MALWARE, SUPPLY_CHAIN, CAMPAIGN, DATA_BREACH, PHISHING
- **As of:** 2026-08-13

## ATT&CK techniques observed

157 techniques observed across 15 of 15 tracked threats. Tactics: Stealth (formerly Defense Evasion) (26), Persistence (20), Command and Control (17), Execution (16), Resource Development (16), Credential Access (12).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 12 of 15 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 12 of 15 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 12 of 15 tracked threats
- [T1105](https://intel.threadlinqs.com/technique/T1105) Ingress Tool Transfer — Command and Control — observed in 12 of 15 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 11 of 15 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 8 of 15 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 8 of 15 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 8 of 15 tracked threats
- [T1057](https://intel.threadlinqs.com/technique/T1057) Process Discovery — Discovery — observed in 7 of 15 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 7 of 15 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 6 of 15 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Credential Access — observed in 6 of 15 tracked threats
- [T1059.001](https://intel.threadlinqs.com/technique/T1059.001) PowerShell — Execution — observed in 6 of 15 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 6 of 15 tracked threats
- [T1083](https://intel.threadlinqs.com/technique/T1083) File and Directory Discovery — Discovery — observed in 6 of 15 tracked threats

## Tracked threats

- [Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2005) — HIGH
- [Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)](https://intel.threadlinqs.com/threat/TL-2026-1645) — HIGH
- [Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS Customer](https://intel.threadlinqs.com/threat/TL-2026-1643) — HIGH
- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM
- [Domestic APT Spear-Phishing Campaigns (May 2026) — LNK/HTA/CHM/JSE Loaders Deploying XenoRAT, Suspected Kimsuky](https://intel.threadlinqs.com/threat/TL-2026-1229) — HIGH
- [ClickFix Campaigns Evolve API-Driven Payload Delivery: Analysis of 3,000 Live Payloads Reveals New Evasion Techniques](https://intel.threadlinqs.com/threat/TL-2026-1027) — HIGH
- [macOS.Gaslight - Rust Backdoor with AI-Analysis Evasion & Prompt Injection](https://intel.threadlinqs.com/threat/TL-2026-0994) — CRITICAL
- [Dark Web Data-Leak Roundup (June 2026): Iran Hajj Organization (168M records), AdressFakta/SUPEReROI Sweden (5.4M+), Chrysler/Salesforce (1TB+, Everest Ransomware), and Crypto-Platform Lead Lists](https://intel.threadlinqs.com/threat/TL-2026-0803) — HIGH
- [DPRK (Kimsuky) Multi-Stage LNK Phishing Campaign Delivering XenoRAT via GitHub-based C2 Targeting South Korea](https://intel.threadlinqs.com/threat/TL-2026-0771) — HIGH
- [Kimsuky (Velvet Chollima) PebbleDash Cluster — HelloDoor, httpMalice, httpTroy/MemLoad & VS Code Remote Tunnel Abuse Against South Korea](https://intel.threadlinqs.com/threat/TL-2026-0626) — HIGH
- [ASEC April 2026 APT Trend Report (South Korea) — Kimsuky-Aligned LNK/PowerShell/AutoIt Spear-Phishing with PubNub C2, GitHub-Hosted HTA & XenoRAT (5 Infection Types)](https://intel.threadlinqs.com/threat/TL-2026-0585) — HIGH
- [Kimsuky CHM Dropper / VBScript Stager / PowerShell Keylogger Kill Chain Recovered from Live C2 (api_reference.chm, check.nid-log.com)](https://intel.threadlinqs.com/threat/TL-2026-0461) — HIGH
- [Screensaver (.SCR) Files Used as Initial Access Vector](https://intel.threadlinqs.com/threat/TL-2026-0104) — HIGH
- [eScan Antivirus Supply Chain Attack - Update Server Compromise](https://intel.threadlinqs.com/threat/TL-2026-0038) — CRITICAL
- [GuptiMiner — North Korean (Kimsuky/APT43) Supply Chain Attack Hijacking eScan Antivirus HTTP Updates via AitM](https://intel.threadlinqs.com/threat/TL-2026-0028) — CRITICAL

## Related CVEs

1 CVE referenced by tracked APT43 activity.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT43
