Skip to content
Auto-CTI
Back to all actors

Kimsuky

Nation-state Espionage North Korea Dormant

Aliases: Velvet Chollima ยท Emerald Sleet ยท Thallium ยท Black Banshee ยท APT43

Mentions
2
First seen
14 May 2026
Last seen
01 Jul 2026

Relevant to you ยท Relevant

Threat focus:
espionage / apt

Origin

North Korea โ€” North Korean RGB

Profile

Kimsuky is a threat group that, according to recent reporting, is targeting organizations with PebbleDash-based tools. A large-scale campaign using ScreenConnect disguised as freeware has also been observed. No details on targeted sectors, regions, or countries are evident from the headlines.

Affected vendors

ScreenConnectConnectWise

Associated malware / tools

PebbleDash

How they operate (MITRE tactics)

Privilege Escalation

Recommended mitigations

Derived from MITRE ATT&CK, mapped to this actor's techniques.

Activity (8 weeks)

31
32
33
34
35
36
37
38

Recent activity

ESC

โ€ฆ