Adversary-emulation profile for Kimsuky (G0094 / Velvet Chollima / Emerald Sleet / THALLIUM / Black Banshee / APT43 / TA427), North Korea's RGB 63rd Research Center cyber-espionage actor.
59
68%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Fix and improve this skill with Tessl
tessl review fix ./packages/decepticon/decepticon/skills/shared/adversary-emulation/kimsuky/SKILL.mdKimsuky (MITRE ATT&CK G0094) is a DPRK-based cyber-espionage group attributed to North Korea's Reconnaissance General Bureau (RGB), specifically the 63rd Research Center, operating since at least 2012. Initially focused on South Korean government entities and think tanks, the group has expanded its aperture to the United States, Japan, Russia, and Europe — consistently targeting individuals and organizations with insight into Korean Peninsula foreign policy, nuclear policy, sanctions, and defense issues. Kimsuky is distinguished by its heavy investment in social engineering and credential phishing over zero-day exploitation: the group impersonates journalists, researchers, diplomats, and think-tank personnel in long-running correspondence campaigns to build trust before delivering malicious payloads or harvesting credentials. Its tooling ranges from commodity RATs (QuasarRAT, gh0st RAT) to a stable of bespoke malware families (BabyShark, AppleSeed, Gold Dragon, KONNI, Troll Stealer) and malicious browser extensions (TRANSLATEXT). Since 2023, Kimsuky has been observed leveraging commercial LLMs for target research and vulnerability analysis, and adopting ClickFix-style social engineering to trick victims into self-executing malicious PowerShell.
[System.Reflection.Assembly]::Load.net localgroup.net user for persistent access.-WindowStyle Hidden); -ErrorAction SilentlyContinue to suppress errors.Get-CimInstance manufacturer checks.C:\Program Files\Common Files\System\Ole DB\ and %TEMP% directories.| Name | ATT&CK ID | Type | Public/Custom |
|---|---|---|---|
| BabyShark | S0414 | VBS/HTA-based reconnaissance backdoor | Custom |
| AppleSeed | S0622 | Modular Windows backdoor (keylogging, screen capture, exfil) | Custom |
| Gold Dragon | S0249 | Windows backdoor with data staging and exfil | Custom |
| Brave Prince | S0252 | Windows backdoor / info stealer | Custom |
| KGH_SPY | S0526 | Modular spyware suite (credential/email/keylog) | Custom |
| CSPY Downloader | S0527 | UAC-bypass downloader with anti-VM checks | Custom |
| NOKKI | S0353 | Windows backdoor with credential hooking | Custom |
| Troll Stealer | S1196 | Go-based comprehensive data stealer (signed with stolen cert) | Custom |
| GoBear | S1197 | Go-based Windows backdoor (signed with stolen cert) | Custom |
| Gomir | S1198 | Go-based Linux backdoor (systemd/cron persistence) | Custom |
| HTTPTroy | S9007 | Windows backdoor with UAC bypass and SIMD obfuscation | Custom |
| TRANSLATEXT | S1201 | Malicious Chrome extension (credential/cookie/email theft) | Custom |
| KONNI | (linked cluster) | RAT with document theft, often delivered via CHM/LNK | Custom |
| FlowerPower | (reported in vendor analysis) | PowerShell-based reconnaissance/collection script | Custom |
| MailFetch.py | (no ATT&CK software ID) | Python email crawler (IMAP-based collection) | Custom |
| MECHANICAL | (no ATT&CK software ID) | Keylogger | Custom |
| GREASE | (no ATT&CK software ID) | Account creation tool for RDP persistence | Custom |
| gh0st RAT | S0032 | Remote access trojan | Public |
| QuasarRAT | S0262 | .NET remote access trojan | Public |
| Amadey | S1025 | Modular downloader/loader | Public |
| Mimikatz | S0002 | Credential dumping | Public |
| PsExec | S0029 | Remote execution | Public |
| Nirsoft WebBrowserPassView / SniffPass | (Nirsoft tools) | Browser password dump / network sniffer | Public |
| PHProxy | (open source) | Modified web proxy for AitM | Public |
| certutil / schtasks / mshta / rundll32 / regsvr32 | S0160 / S0111 / built-in | LOLBins | Built-in |
Authorized-use caveat: Execute the following ONLY within the documented rules of engagement, target scope, and time window of an authorized engagement. Never run credential-harvesting, social-engineering, or financial-theft techniques outside an explicitly sanctioned scope.
Map Kimsuky's signature plays to Decepticon's own capabilities:
C:\Program Files\Common Files\System\Ole DB\; archive with QuickZip or PowerShell Compress-Archive, rename archives (init.zip → init.dat); exfiltrate on 10-minute automated intervals to cloud services.Get-CimInstance to detect and terminate in virtual environments. Use mutex-based execution guardrails to prevent duplicate instances. Apply junk code insertion and SIMD-based string obfuscation for payload hardening.4484f85
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.