type: entity Β· created: 2026-07-24 Β· updated: 2026-07-24 Β· tags: [apt-group, nation-state, north-korea, supply-chain, espionage] Β· confidence: high Β· affected_sectors: [technology] Β· au_impact: false
Kimsuky β North Korea-Linked APT Group
Kimsuky (also tracked as APT43, Velvet Chollima, Emerald Sleet) is a North Korea-linked advanced persistent threat group known for cyber espionage operations targeting think tanks, academic institutions, and government entities β particularly those focused onζι² affairs and foreign policy.
Recent Activity (July 2026)
As reported by The Record, Kimsuky breached South Korean software vendors in a new supply-chain style campaign. The operation targeted the software supply chain to reach downstream victims, continuing the group's focus on the Korean peninsula.
Background
| Attribute | Detail |
|---|---|
| Aliases | APT43, Velvet Chollima, Emerald Sleet, Thallium |
| Attribution | Democratic People's Republic of Korea (DPRK) |
| Primary Focus | Cyber espionage β foreign policy,ζι² affairs, nuclear policy |
| Active Since | ~2012 |
Known TTPs
- Spear-phishing with malicious attachments and links
- Reconnaissance of academic and policy research networks
- Credential harvesting via custom malware and social engineering
- Supply chain compromise of software vendors to reach downstream targets (July 2026 campaign)
Related Pages
- Silver Fox β China-linked cybercrime group (different nation-state, similar targeting of software supply chain)
- Uat 7810 β China-linked APT targeting Taiwan critical infrastructure (regional state-sponsored context)