https://thehackernews.com/2023/12/us-treasury-sanctions-north-korean.html
U.S. Treasury Sanctions North Korean Kimsuky Hackers and 8 Foreign-Based Agents
OFAC sanctions North Korea-linked group Kimsuky and 8 agents for supporting WMD programs.
https://thehackernews.com/2024/12/north-korean-kimsuky-hackers-use.html?ref=lefilcyber.fr
North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks
Kimsuky hackers use Russian email addresses and fake cloud storage alerts to steal user credentials in new phishing campaign.
north korean
https://thehackernews.com/2025/12/kimsuky-spreads-docswap-android-malware.html
Kimsuky Spreads DocSwap Android Malware via QR Phishing Posing as Delivery App
North Korean group Kimsuky uses QR code phishing sites posing as CJ Logistics to spread DocSwap Android malware with RAT capabilities.
android malware
https://thehackernews.com/2023/12/kimsuky-hackers-deploying-appleseed.html
Kimsuky Hackers Deploying AppleSeed, Meterpreter, and TinyNuke in Latest Attacks
North Korean nation-state actors are using spear-phishing attacks to seize control of computers, deploying tools like AppleSeed and Meterpreter.
kimsukyhackersdeployingappleseedmeterpreter
https://thehackernews.com/2023/05/north-korean-kimsuky-hackers-strike.html
North Korean Kimsuky Hackers Strike Again with Advanced Reconnaissance Malware
Kimsuky, the North Korean APT group, is back in action! They're using a new custom malware called RandomQuery to conduct reconnaissance.
north koreankimsukyhackersstrikeadvanced
https://thehackernews.com/2024/02/kimsukys-new-golang-stealer-troll-and.html?m=1
Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea
North Korean APT Kimsuky caught using new Golang-based info stealer "Troll Stealer" and malware "GoBear," both signed with stolen certificates.
s new
https://thehackernews.com/2024/02/kimsukys-new-golang-stealer-troll-and.html
Kimsuky's New Golang Stealer 'Troll' and 'GoBear' Backdoor Target South Korea
North Korean APT Kimsuky caught using new Golang-based info stealer "Troll Stealer" and malware "GoBear," both signed with stolen certificates.
s new
https://thehackernews.com/2023/03/german-and-south-korean-agencies-warn.html
German and South Korean Agencies Warn of Kimsuky's Expanding Cyber Attack Tactics
German and South Korean intel agencies warn of #Kimsuky cyberattacks, targeting Gmail inboxes through rogue browser extensions
https://www.techradar.com/pro/lazarus-and-kimsuky-prove-why-infrastructure-level-analysis-is-crucial-for-cybersecurity
Lazarus and Kimsuky prove why infrastructure-level analysis is crucial for cybersecurity | TechRadar
Apr 10, 2026 - Infrastructure hunting is no longer a supporting discipline - it is the vantage point