Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The U.S. government’s October 2020 Kimsuky advisory described a North Korean threat actor focused on intelligence collection, with social engineering and spear-phishing among its reported methods. It covered activity and technical observations through July 2020, so it is a historical account—not a complete or current profile of the group.

What the October 2020 advisory said

The joint advisory, AA20-301A, was published on October 27, 2020, by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and U.S. Cyber Command’s Cyber National Mission Force (CNMF). Its underlying open-source and intelligence reporting extended through July 2020.

The agencies assessed that Kimsuky was likely tasked with collecting intelligence in support of North Korean government interests. They highlighted foreign-policy and national-security issues involving the Korean Peninsula, nuclear policy, and sanctions. The advisory estimated that the group had “most likely been operating since 2012”; that is an estimate of operating history, not a measure of victim numbers or prevalence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who the advisory described as targets

The reported activity affected people and organizations in South Korea, Japan, and the United States. The agencies highlighted subject-matter experts, think tanks, and entities associated with the South Korean government. The advisory’s focus on these targets reflects what had been reported by its July 2020 cutoff, not a guarantee that the same targeting continued afterward.

How Kimsuky reportedly sought access

Social engineering and spear-phishing featured prominently in the advisory’s account, alongside watering-hole activity. A contemporary summary by Ionut Arghire in SecurityWeek described tailored messages and malicious attachments, including approaches framed as interview requests from people impersonating South Korean reporters. Other lures invoked login security alerts. The reporting also described benign messages used to establish trust before a malicious approach.

The practical lesson is not that every unsolicited interview request or account alert is malicious. It is that a plausible, topic-specific message can be part of an intrusion attempt, so recipients should verify the sender and any requested action through a separate, trusted channel rather than relying on the message’s appearance.

Rank #2
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
  • Cybersecurity.
  • This merchandise, which shows a computer cybersecurity word cloud design, is ideal for computer programmers, coders, and hackers. It is also for software engineer or software developers, as well as information technology or computer science majors.
  • Hardcover journal with 240 line-ruled pages (120 sheets)
  • Built-in elastic closure and ribbon bookmark
  • Includes an expandable inner storage pocket and a pen holder

What the advisory reported after compromise

The technical account is useful as a record of reported behavior, but its examples should not be treated as a checklist of current Kimsuky activity or as proof that every intrusion used every technique.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Scripts, persistence, and system information

The advisory described an HTA file using mshta.exe to fetch and run an encoded BabyShark Visual Basic Script (VBS) file. In the reported chain, the script created persistence through a registry key, collected system information, and sent it to command-and-control servers.

Credential and file collection

Reported collection included credentials and documents, including Hangul Word Processor and Microsoft Office files. The agencies also described credential-harvesting and memory-dumping tools, malicious browser extensions, and use of Windows utilities. These observations illustrate the kinds of data and access the advisory said the actor sought; they do not establish which tools remain in use.

Other Windows and macOS behavior

The 2020 account discussed activity involving both Windows and macOS. It reported use of PowerShell and Remote Desktop Protocol (RDP), web shells for file management, altered processes, and changes to autostart behavior or file associations. It also described persistence or privilege-escalation techniques involving Startup-folder scripts and services, and code injected into explorer.exe.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How defenders should use this historical account

AA20-301A can help with threat modeling: it documents the agencies’ historical account of Kimsuky’s social-engineering approaches, collection goals, and technical behaviors. It is not a live threat feed. The advisory’s indicators and technical detail should be checked directly in the original document before being used in detection or incident-response work; the cited material does not establish that 2020 indicators remain active or that a particular commercial product is required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not confuse this advisory with the separate 2024 joint government advisory, AA24-207A. That publication concerns Andariel and its espionage campaign. It is not, by itself, a Kimsuky-specific update.

What is and is not established now

The cited sources establish what U.S. agencies reported about Kimsuky through July 2020 and how they characterized the group at that time. They do not settle the group’s activity, targets, tools, or indicators as of 2026. A current operational assessment requires newer Kimsuky-specific reporting.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.