#Kimsuky

DPRK-aligned APT (also tracked as Velvet Chollima, TA427, Black Banshee)

Subscribe (RSS)


#Kimsuky

DPRK-aligned APT (Velvet Chollima, TA427, Black Banshee)

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #Kimsuky

Week

10

IOCs tagged #Kimsuky

Month

88

IOCs tagged #Kimsuky

Year

13,256

IOCs tagged #Kimsuky

Counts as of 2026-08-29. Regenerated daily.

About #Kimsuky

  • Threat actor: DPRK-aligned APT active since at least 2012, also tracked as Velvet Chollima (CrowdStrike), TA427 (Proofpoint) and Black Banshee (Mandiant).
  • Targets: South Korean government, defense and academic organisations; expanded to think tanks and research institutions in the US, Japan and Europe.
  • Tactics: spear-phishing with weaponised HWP and PDF, custom backdoors (BabyShark, AppleSeed, GoldDragon), credential harvesting on legacy email portals, fake login pages.
  • References: MITRE ATT&CK G0094 · CISA AA20-301A.

Recent IOCs tagged #Kimsuky

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/kimsuky.

Date Type Value Source
Aug 26, 18:00 domain k-store.login-accounts.dynu.net @phatomcandle
Aug 26, 18:00 url http://k-store.login-accounts.dynu.net @phatomcandle
Aug 24, 06:53 sha256 6e6addf3e7287cf160054ef4647f8c67754f3cdc6efbdf21f117cb98c4c9... @nextronresearch
Aug 24, 06:53 sha256 49000d685f7c2ae1ddd5d40ca754562318e49c3a2534540951490f22756a... @nextronresearch
Aug 24, 06:53 sha256 44dc1939dcaea681f5c39ed6f5f81a80ca5f59e72be7f938ac3afe5adb48... @nextronresearch
Aug 24, 06:53 sha256 018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a8... @nextronresearch
Aug 24, 06:53 sha256 864ed6df1ba1b615f2db460666e2aee72a025754f5d78be3d83ec8e3c41d... @nextronresearch
Aug 24, 06:53 sha256 169586b6eb36b17520ef5afd206da86c4de89eb01d6294ba9631414271ba... @nextronresearch
Aug 23, 18:00 domain k-cloud.auth-accounts.dynuddns.com @phatomcandle
Aug 23, 18:00 url http://k-cloud.auth-accounts.dynuddns.com @phatomcandle

Related tags

Tags that frequently co-occur with #Kimsuky.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is Kimsuky?

Kimsuky is a DPRK-aligned advanced persistent threat (APT) group active since at least 2012. It is also tracked under the names Velvet Chollima (CrowdStrike), TA427 (Proofpoint) and Black Banshee (Mandiant). Kimsuky targets South Korean government, defense and academic organisations, and has expanded to research institutions in the United States, Japan and Europe. The group is known for spear-phishing, weaponised HWP and PDF documents, and custom backdoors such as BabyShark, AppleSeed and GoldDragon.

Is Kimsuky the same as Lazarus?

No. Both Kimsuky and Lazarus are DPRK-aligned, but they are distinct clusters tracked by different attribution analysts and target different verticals. Lazarus focuses on financial gain (cryptocurrency exchanges, banks). Kimsuky focuses on intelligence collection (foreign policy, defense, academic). The #Lazarus tag on TweetFeed groups its own IOCs separately.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Kimsuky-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this Kimsuky subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

Kimsuky IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).