Kimsuky Operation SmokeScreen

Kimsuky spearphishing campaign targeting South Korean think tanks, government advisors and academic institutions.

Start date
1 January 2019
End date
Techniques
15

Attributed actors

Techniques (15)

collection2
T1114.001Local Email Collection
T1113Screen Capture
command-and-control2
T1105Ingress Tool Transfer
T1071.001Web Protocols
discovery2
T1082System Information Discovery
T1083File and Directory Discovery
execution2
T1059.003Windows Command Shell
T1059.001PowerShell
exfiltration1
T1041Exfiltration Over C2 Channel
initial-access2
T1566.002Spearphishing Link
T1566.001Spearphishing Attachment
persistence1
T1547.001Registry Run Keys / Startup Folder
privilege-escalation2
T1547.001Registry Run Keys / Startup Folder
T1055Process Injection
stealth3
T1070.004File Deletion
T1055Process Injection
T1027Obfuscated Files or Information

Indicators of compromise

No IOCs linked to this campaign yet.