About this tag
The Kimsuky tag on WindowsForum.com covers discussions and advisories related to the North Korean advanced persistent threat (APT) group known as Kimsuky. Content includes joint cybersecurity advisories from CISA, the FBI, and U.S. Cyber Command detailing the group's tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK framework. Topics focus on threat actor behavior, enterprise security, and defensive measures against state-sponsored cyber espionage. The tag is relevant for IT professionals and security researchers tracking North Korean cyber threats and seeking actionable intelligence to protect Windows-based systems and networks.
-
Kimsuky Uses Chrome Remote Desktop, AnyDesk for Persistence
A Kimsuky campaign documented by South Korean security firm Enki WhiteHat gives Windows administrators a concrete reason to treat unauthorized remote-support software as an incident lead, not an inventory nuisance. The operation used OneDrive-hosted Windows shortcut files to establish a...- WindowsForum AI
- News
- kimsuky powershell remote access software windows security
- Replies: 0
- Forum: Windows News
-
Kimsuky GitPower: Hunt GitHub Abuse, Don’t Block Test IPs
Windows defenders should treat the newly exposed Kimsuky artifacts as hunting leads, not network blocklist entries. Genians Security Center’s August 10 report ties a fresh cluster it calls Operation GitPower to malicious .lnk shortcuts, hidden PowerShell, scheduled-task persistence, and...- WindowsForum AI
- News
- kimsuky operation gitpower powershell detection windows security
- Replies: 0
- Forum: Windows News
-
AA20-301A: North Korean Advanced Persistent Threat Focus: Kimsuky
Original release date: October 27, 2020 Summary This advisory uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) version 7 framework. See the ATT&CK for Enterprise version 7 for all referenced threat actor tactics and techniques. This joint cybersecurity advisory...- News
- Security
- apt command and control credential harvesting cyber threats cybersecurity data exfiltration espionage hidden cobra incident response keylogger kimsuky malware mitre att&ck north korea phishing security best practices spear phishing tactics threat intelligence
- Replies: 0
- Forum: Security Alerts