Thallium is a apt_group tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed November 11, 2025; most recent activity November 11, 2025.
Thallium is a North Korea–linked Advanced Persistent Threat (APT) group known for long-running espionage campaigns against government, defense, finance, and critical infrastructure sectors. It deploys custom malware and backdoors, with a focus on credential theft and data exfiltration, marking it as a persistent state-sponsored threat in cyberspace.
In September 2025, the North Korea-linked APT group Konni, also known as Kimsuky, targeted users by posing as counselors to steal data and wipe Android phones using Google Find Hub. The attacks also affected Windows…