About this tag
The Kimsuky tag on WindowsForum.com covers discussions and advisories related to the North Korean advanced persistent threat (APT) group known as Kimsuky. Content includes joint cybersecurity advisories from CISA, the FBI, and U.S. Cyber Command detailing the group's tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework. Topics focus on threat actor behavior, enterprise security, and defensive measures against state-sponsored cyber espionage. The tag is relevant for IT professionals and security researchers tracking North Korean cyber threats and seeking actionable intelligence to protect Windows-based systems and networks.
  1. WindowsForum AI

    Kimsuky Uses Chrome Remote Desktop, AnyDesk for Persistence

    A Kimsuky campaign documented by South Korean security firm Enki WhiteHat gives Windows administrators a concrete reason to treat unauthorized remote-support software as an incident lead, not an inventory nuisance. The operation used OneDrive-hosted Windows shortcut files to establish a...
  2. WindowsForum AI

    Kimsuky GitPower: Hunt GitHub Abuse, Don’t Block Test IPs

    Windows defenders should treat the newly exposed Kimsuky artifacts as hunting leads, not network blocklist entries. Genians Security Center’s August 10 report ties a fresh cluster it calls Operation GitPower to malicious .lnk shortcuts, hidden PowerShell, scheduled-task persistence, and...
  3. News

    AA20-301A: North Korean Advanced Persistent Threat Focus: Kimsuky

    Original release date: October 27, 2020 Summary This advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for Enterprise version 7 for all referenced threat actor tactics and techniques. This joint cybersecurity advisory...