Kimsuki — Threat Actor Profile, Campaigns & Targets

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
January 8, 2026
Last Seen
January 8, 2026

Kimsuki is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed January 8, 2026; most recent activity January 8, 2026.

Overview

Kimsuky is a North Korea–linked APT group known for cyber-espionage campaigns targeting government, think tanks, and other organizations. A recent FBI warning indicates the group is increasingly using QR codes as phishing lures to target U.S. organizations, signaling a shift toward QR-based social engineering and ongoing credential/malware delivery campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs — Bleepingcomputer · January 8, 2026

CVSS v3.1 Breakdown