Kimsuky Thallium Operations

Microsoft-attributed Kimsuky/Thallium campaign targeting policy researchers, think tanks and human rights organisations.

Start date
1 December 2019
End date
Techniques
16

Attributed actors

Techniques (16)

collection2
T1114.002Remote Email Collection
T1113Screen Capture
command-and-control2
T1105Ingress Tool Transfer
T1071.001Web Protocols
discovery2
T1082System Information Discovery
T1083File and Directory Discovery
execution3
T1059.003Windows Command Shell
T1059.001PowerShell
T1053.005Scheduled Task
exfiltration1
T1041Exfiltration Over C2 Channel
initial-access3
T1566.002Spearphishing Link
T1078Valid Accounts
T1566.001Spearphishing Attachment
persistence3
T1078Valid Accounts
T1547.001Registry Run Keys / Startup Folder
T1053.005Scheduled Task
privilege-escalation3
T1078Valid Accounts
T1547.001Registry Run Keys / Startup Folder
T1053.005Scheduled Task
reconnaissance1
T1598.003Spearphishing Link
stealth2
T1078Valid Accounts
T1027Obfuscated Files or Information

Indicators of compromise

No IOCs linked to this campaign yet.

Kimsuky Thallium Operations — Campaign | Fancy Intel