Kimsuky Operation — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 2, 2025
Last Seen
December 2, 2025

Kimsuky Operation is a North Korea–linked cyber-espionage campaign attributed to the Kimsuky group, focused on political and governmental targets.

Overview

Kimsuky Operation is a North Korea–linked cyber-espionage campaign attributed to the Kimsuky group, focused on political and governmental targets. Recent reporting indicates the group distributes KimJongRAT using illicit HTA files, highlighting HTA-based delivery as a key tactic to establish backdoor access on Windows systems.

Related Threat Clusters

  • KimJongRAT Malware Targets Windows Users via Phishing Campaign

    The KimJongRAT malware, linked to the North Korean Kimsuky group, is targeting Windows systems through phishing emails. These emails contain a ZIP archive disguised as a tax notice, which, when opened, executes a…

    2 articles · Updated December 2, 2025

Recent Intelligence Reports

  • Illicit HTA files facilitate KimJongRAT distribution — Scworld · December 2, 2025

CVSS v3.1 Breakdown