Worked example · 2018-20
APT43 / Kimsuky crypto-funded espionage — 2018–2025
Summary
APT43/Kimsuky has been active since at least 2012, with a primary mission of strategic cyber-espionage targeting government, diplomatic, academic, and think-tank entities in South Korea, Japan, the United States, and Europe. The cluster's cryptocurrency-funded operational model was first publicly characterised in detail by Mandiant's March 2023 APT43 report, which documented the cluster's use of cryptocurrency theft to fund its espionage operations — a "self-funding" model that reduces dependence on Pyongyang's central budget allocation.
The cluster's crypto-relevant TTPs include: (1) spear-phishing campaigns against cryptocurrency exchange employees and crypto-startup personnel for credential harvesting; (2) deployment of the BabyShark and MagicRAT malware families against crypto-adjacent targets; (3) laundering of stolen cryptocurrency through the broader DPRK laundering infrastructure shared with Lazarus Group and BlueNoroff.
The boundary between G07 (APT43/Kimsuky) and G01 (Lazarus Group/APT38) is operationally meaningful but not always cleanly resolvable per-incident from public reporting: both clusters target crypto entities, both launder through shared infrastructure, and both operate under RGB authority. OAK records the partition based on mission priority (espionage vs. financial theft), TTP fingerprint (spear-phishing vs. supply-chain compromise), and industry-forensic cluster taxonomy (Mandiant, CrowdStrike, Microsoft, KISA).
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| 2012 | Kimsuky activity first observed; initial targeting of South Korean government and academic entities | (pre-crypto) |
| 2018–2019 | Kimsuky crypto-funded operational model emerges; first documented crypto-targeted spear-phishing campaigns | T15.001 / T4.001 |
| 2023-03 | Mandiant APT43 report publicly characterises the crypto-funded operational model in technical detail | (attribution milestone) |
| 2023-06 | Republic of Korea sanctions Kimsuky — first South Korean sanctions against a North Korean hacking group | (attribution milestone) |
| 2023-11 | OFAC SDN designation of Kimsuky; U.S. Treasury formally attributes the cluster to DPRK RGB | (attribution milestone) |
| Continuing | Kimsuky crypto-targeted operations remain active at v0.1 cutoff | (ongoing) |
Public references
- Mandiant: APT43 — An investigation into the DPRK's strategic cyber-espionage group, March 28, 2023 (
[mandiantapt432023]). - OFAC: Kimsuky SDN designation, November 30, 2023 (
[ofac2023kimsuky]). - Republic of Korea Ministry of Foreign Affairs / NIS: Kimsuky sanctions designation, June 2, 2023 (
[mofakimsuky2023]). - BfV / NIS: Joint advisory on Kimsuky TTPs, March 20, 2023 (
[bfvnis2023kimsuky]).