Home Β· Wiki Β· Entities & Threat Actors
type: entity Β· created: 2026-07-24 Β· updated: 2026-07-24 Β· tags: [apt-group, nation-state, north-korea, supply-chain, espionage] Β· confidence: high Β· affected_sectors: [technology] Β· au_impact: false

Kimsuky β€” North Korea-Linked APT Group

Kimsuky (also tracked as APT43, Velvet Chollima, Emerald Sleet) is a North Korea-linked advanced persistent threat group known for cyber espionage operations targeting think tanks, academic institutions, and government entities β€” particularly those focused on朝鲜 affairs and foreign policy.

Recent Activity (July 2026)

As reported by The Record, Kimsuky breached South Korean software vendors in a new supply-chain style campaign. The operation targeted the software supply chain to reach downstream victims, continuing the group's focus on the Korean peninsula.

Background

Attribute Detail
Aliases APT43, Velvet Chollima, Emerald Sleet, Thallium
Attribution Democratic People's Republic of Korea (DPRK)
Primary Focus Cyber espionage β€” foreign policy,朝鲜 affairs, nuclear policy
Active Since ~2012

Known TTPs

  • Spear-phishing with malicious attachments and links
  • Reconnaissance of academic and policy research networks
  • Credential harvesting via custom malware and social engineering
  • Supply chain compromise of software vendors to reach downstream targets (July 2026 campaign)

Related Pages

  • Silver Fox β€” China-linked cybercrime group (different nation-state, similar targeting of software supply chain)
  • Uat 7810 β€” China-linked APT targeting Taiwan critical infrastructure (regional state-sponsored context)