Netskope Threat Labs

Kimsuky

ATP Sandbox Adv. HeuristicsAV

Kimsuky is malware associated with a North Korean threat group that specializes in intelligence collection against government, academic, and media targets. The group's tooling blends phishing pages, malicious documents, and lightweight backdoors that steal credentials and files, and its operators adapt lures to current events with unusual speed. Its long campaign history shows a patient operation focused on espionage rather than destruction or ransom.

First seen
March 2022
Last seen
October 2026
KimSuky
Alert Name
Android.Backdoor.Kimsuky
Android.Trojan.Kimsuky
Document-Office.Backdoor.Kimsuky
Document-Word.Backdoor.Kimsuky
Document-Word.Trojan.Kimsuky
Document-XML.Backdoor.Kimsuky
Dropped:Trojan.Kimsuky.188
Dump:Generic.MSC.Kimsuky.A.FFFFFFFE
Gen:Variant.Kimsuky.100
Gen:Variant.Kimsuky.13