#Kimsuky

DPRK-aligned APT (also tracked as Velvet Chollima, TA427, Black Banshee)

Subscribe (RSS)


#Kimsuky

DPRK-aligned APT (Velvet Chollima, TA427, Black Banshee)

Subscribe (RSS)


IOCs by window

Today

0

IOCs tagged #Kimsuky

Week

6

IOCs tagged #Kimsuky

Month

94

IOCs tagged #Kimsuky

Year

13,244

IOCs tagged #Kimsuky

Counts as of 2026-09-05. Regenerated daily.

About #Kimsuky

  • Threat actor: DPRK-aligned APT active since at least 2012, also tracked as Velvet Chollima (CrowdStrike), TA427 (Proofpoint) and Black Banshee (Mandiant).
  • Targets: South Korean government, defense and academic organisations; expanded to think tanks and research institutions in the US, Japan and Europe.
  • Tactics: spear-phishing with weaponised HWP and PDF, custom backdoors (BabyShark, AppleSeed, GoldDragon), credential harvesting on legacy email portals, fake login pages.
  • References: MITRE ATT&CK G0094 · CISA AA20-301A.

Recent IOCs tagged #Kimsuky

Latest 10 IOCs from the past 30 days. Live JSON: api.tweetfeed.live/v1/month/kimsuky.

Date Type Value Source
Sep 03, 18:00 domain login-accounts.dynu.net @phatomcandle
Sep 03, 18:00 url http://www.login-accounts.dynu.net @phatomcandle
Sep 01, 18:00 domain kakao-user.login-accounts.dynu.net @phatomcandle
Sep 01, 18:00 url http://kakao-user.login-accounts.dynu.net @phatomcandle
Aug 30, 18:00 domain k-store.auth-accounts.dynu.org @phatomcandle
Aug 30, 18:00 url http://k-store.auth-accounts.dynu.org @phatomcandle
Aug 26, 18:00 domain k-store.login-accounts.dynu.net @phatomcandle
Aug 26, 18:00 url http://k-store.login-accounts.dynu.net @phatomcandle
Aug 24, 06:53 sha256 6e6addf3e7287cf160054ef4647f8c67754f3cdc6efbdf21f117cb98c4c9... @nextronresearch
Aug 24, 06:53 sha256 49000d685f7c2ae1ddd5d40ca754562318e49c3a2534540951490f22756a... @nextronresearch

Related tags

Tags that frequently co-occur with #Kimsuky.

See all tags on the Dashboard or browse the full IOC feed.

Frequently asked questions

What is Kimsuky?

Kimsuky is a DPRK-aligned advanced persistent threat (APT) group active since at least 2012. It is also tracked under the names Velvet Chollima (CrowdStrike), TA427 (Proofpoint) and Black Banshee (Mandiant). Kimsuky targets South Korean government, defense and academic organisations, and has expanded to research institutions in the United States, Japan and Europe. The group is known for spear-phishing, weaponised HWP and PDF documents, and custom backdoors such as BabyShark, AppleSeed and GoldDragon.

Is Kimsuky the same as Lazarus?

No. Both Kimsuky and Lazarus are DPRK-aligned, but they are distinct clusters tracked by different attribution analysts and target different verticals. Lazarus focuses on financial gain (cryptocurrency exchanges, banks). Kimsuky focuses on intelligence collection (foreign policy, defense, academic). The #Lazarus tag on TweetFeed groups its own IOCs separately.

How is this list updated?

Every 15 minutes. The TweetFeed pipeline scrapes RSS feeds from public Twitter/X security researcher accounts and lists, extracts IOCs, tags them with the relevant malware family or threat actor, and republishes the result in CSV, JSON and RSS. Kimsuky-tagged IOCs are surfaced on this page within the next 15-minute tick. The page itself is regenerated daily by a GitHub Action.

What is the license? Can I use this commercially?

All TweetFeed IOC data, including this Kimsuky subset, is released under CC0 1.0 Universal (Public Domain Dedication). No attribution required, no warranty. Commercial use is allowed. The TweetFeed website code and branding are not covered by CC0.

License

Kimsuky IOC data: CC0 1.0 Public Domain. No attribution required, no warranty. Source code for the pipeline: github.com/0xDanielLopez/TweetFeed (MIT).