Threadlinqs IntelligenceStart free

Threat actorNorth KoreaTracked since 2026-02

Kimsuky

Also known as:Kimsuky - G0094APT43Black BansheeEarth KumihoEmerald SleetG0086Operation Stolen PencilPatheticSlugSparkling PiscesSpringtailTA427THALLIUM

As of 2026-08-13, Kimsuky is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 15 threats spanning apt, malware, supply chain. Also known as Kimsuky - G0094, APT43, Black Banshee, Earth Kumiho. ATT&CK coverage spans 157 techniques across 16 tactics in 15 of 15 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1082 (System Information Discovery).

Tracked threats
153 critical · 11 high · 1 medium
First seen
2026-02-02
Last seen
2026-08-13
ATT&CK techniques
157across 15 of 15 threats
Related CVEs
1Referenced by its activity
Attribution
North KoreaNation or origin
Nation: North Korea · 15 tracked threat(s) · Categories: APT, MALWARE, SUPPLY_CHAIN, CAMPAIGN, DATA_BREACH, PHISHING

Activity timeline

Kimsuky appears in 15 tracked threats between and ; the busiest month was 2026-07 with 5 reports.

ATT&CK techniques observed

157 techniques observed across 15 of 15 tracked threats · Stealth (formerly Defense Evasion) (26), Persistence (20), Command and Control (17), Execution (16), Resource Development (16), Credential Access (12)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 12 of 15 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 12 of 15 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 12 of 15 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 12 of 15 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 11 of 15 tracked threats
  • T1005 Data from Local System — Collectionobserved in 8 of 15 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 8 of 15 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 8 of 15 tracked threats
  • T1057 Process Discovery — Discoveryobserved in 7 of 15 tracked threats
  • T1566 Phishing — Initial Accessobserved in 7 of 15 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 6 of 15 tracked threats
  • T1056.001 Keylogging — Credential Accessobserved in 6 of 15 tracked threats
  • T1059.001 PowerShell — Executionobserved in 6 of 15 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 6 of 15 tracked threats
  • T1083 File and Directory Discovery — Discoveryobserved in 6 of 15 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked Kimsuky activity