Kimsuky
Nation-state Espionage North Korea Dormant
Aliases: Velvet Chollima ยท Emerald Sleet ยท Thallium ยท Black Banshee ยท APT43
- Mentions
- 2
- First seen
- 14 May 2026
- Last seen
- 01 Jul 2026
Relevant to you ยท Relevant
- Threat focus:
- espionage / apt
Origin
North Korea โ North Korean RGB
Profile
Kimsuky is a threat group that, according to recent reporting, is targeting organizations with PebbleDash-based tools. A large-scale campaign using ScreenConnect disguised as freeware has also been observed. No details on targeted sectors, regions, or countries are evident from the headlines.
Affected vendors
ScreenConnectConnectWise
Associated malware / tools
PebbleDash
How they operate (MITRE tactics)
Recommended mitigations
Derived from MITRE ATT&CK, mapped to this actor's techniques.