OAK — OnChain Attack Knowledge

Threat actor · OAK-G07

OAK-G07 — APT43 / Kimsuky (DPRK espionage-and-self-funding cluster)

Aliases
APT43 (Mandiant), Kimsuky (industry-default name; in widest current public use; tracked under external Group ID G0094), Velvet Chollima (CrowdStrike), Black Banshee, Emerald Sleet (Microsoft), Thallium (Microsoft legacy), TA427 (Proofpoint), ARCHIPELAGO (Google TAG), Nickel Kimball, Springtail. For OAK-G07 purposes the cluster is the DPRK Reconnaissance General Bureau (RGB) sub-element whose primary mission is strategic cyber-espionage with cryptocurrency theft and laundering as a self-funding support function — operationally and missionally distinct from the OAK-G01 Lazarus Group / APT38 / BlueNoroff cluster whose primary mission is regime-revenue-generating crypto theft, and from the OAK-G04 IT-worker-placement scheme.
First observed in crypto
approximately 2018–2019 (Kimsuky activity dates to at least 2012 per multiple national-CERT advisories; the cryptocurrency-funded operational model is documented from Mandiant's 2018-onwards tracking forward, with public characterisation crystallising in the March 2023 Mandiant APT43 report).
Attribution status
confirmed at the cluster-and-state-attribution level — U.S. Department of the Treasury OFAC SDN designation of Kimsuky on November 30, 2023 ([ofac2023kimsuky], Treasury press release JY1938) carried out in coordination with Australia, Japan, and the Republic of Korea, attributing the cluster to the DPRK Reconnaissance General Bureau (RGB) and citing intelligence-gathering in support of the DPRK's strategic objectives following the November 1, 2023 reconnaissance-satellite launch; Republic of Korea sanctions designation of Kimsuky by the Ministry of Foreign Affairs / NIS, June 2, 2023 ([mofakimsuky2023]), the first time South Korea sanctioned a North Korean hacking group; joint cyber-security advisory of March 20, 2023 issued by the German Bundesamt für Verfassungsschutz (BfV) and the Republic of Korea National Intelligence Service (NIS) characterising Kimsuky's tooling and TTPs ([bfvnis2023kimsuky]); Mandiant APT43 report of March 28, 2023 attributing the cluster to the RGB at moderate confidence and documenting the cryptocurrency-funded operational model in technical detail ([mandiantapt432023]); external Group ID G0094 with sustained multi-vendor corroboration (CrowdStrike, Microsoft, Proofpoint, Google TAG, Recorded Future, Kaspersky). Attribution that specific cryptocurrency-theft incidents are downstream of an OAK-G07 placement (rather than an OAK-G01 placement) is inferred-strong in most cases — the cluster boundary between G01 (BlueNoroff / APT38 financial-theft sub-cluster) and G07 (APT43 / Kimsuky espionage-and-self-funding sub-cluster) is operationally meaningful but not always cleanly resolvable per-incident from public reporting.
Active
yes (as of v0.1) — sanctions tempo sustained through 2024–2026; Mandiant-, CrowdStrike-, and Microsoft-tracked campaigns ongoing; recent reporting documents continued targeting of cryptocurrency-wallet credentials (MetaMask, Trust Wallet) via VBScript / PowerShell loaders alongside the cluster's traditional spear-phishing-against-policy-targets campaigns.

Description

OAK-G07 is the APT43 / Kimsuky cluster: a DPRK-attributed cyber-actor cluster under the Reconnaissance General Bureau (RGB) — the same parent organisation as OAK-G01 Lazarus Group — but operationally distinct from G01 along three axes. (1) Primary mission: G07 is primarily a strategic cyber-espionage cluster collecting on foreign-policy, nuclear, sanctions-policy, and inter-Korean issues; G01 (and specifically the APT38 / BlueNoroff sub-cluster within G01) is primarily a regime-revenue cluster. Per Mandiant's March 2023 characterisation, "APT43 steals and launders enough cryptocurrency to buy operational infrastructure in a manner aligned with North Korea's juche state ideology of self-reliance, therefore reducing fiscal strain on the central government" — i.e., G07's crypto operations fund G07's own espionage activity, in contrast to G01 (APT38) operations that bring funds in for the regime as a whole. (2) Targeting profile: G07 targets diplomats, journalists, foreign-policy and nuclear think-tank researchers, defectors, government bodies, and academic experts on Korean Peninsula and DPRK issues; G01 targets exchanges, bridges, custody vendors, and crypto-firm engineers. (3) Dominant TTPs: G07 is spear-phishing-and-credential-harvesting heavy with sustained social-engineering rapport-building under fabricated journalist / academic / think-tank personas, plus malicious browser-extension and Android-app deployment for Gmail-and-cloud exfiltration; G01 is supply-chain-and-validator-key-compromise heavy with engineering-grade intrusion tradecraft.

The cluster's modern public profile begins with the Mandiant APT43 report of March 28, 2023 ([mandiantapt432023]), which named the cluster, attributed it to the RGB at moderate confidence, and documented the cryptocurrency-funded operational model in detail — including the cluster's distinctive hash-rental-and-cloud-mining laundering technique, in which stolen cryptocurrency is used to purchase hash power from cloud-mining providers, with mining proceeds delivered to attacker-selected wallets that have no on-chain association with the original theft (a laundering rail that produces mined-coin output that is structurally clean from a cluster-attribution perspective). Mandiant additionally tracked more than 10 million phishing NFTs delivered by the cluster across multiple blockchains from June 2022 onward, a volume-led credential-harvesting and wallet-drain technique distinct from the small-N high-value extraction profile that defines G01. The June 2, 2023 Republic of Korea Ministry of Foreign Affairs designation ([mofakimsuky2023]) was the first time South Korea sanctioned a DPRK hacking group as such — a sanctions-policy threshold event that brought G07 into the formally-designated category, and was followed on November 30, 2023 by the U.S. Treasury OFAC SDN designation of Kimsuky alongside eight DPRK foreign-based agents ([ofac2023kimsuky], Treasury JY1938), coordinated with Australia, Japan, and the Republic of Korea. The March 20, 2023 BfV / NIS joint advisory ([bfvnis2023kimsuky]) is the canonical operational write-up of the cluster's malicious-Chrome-extension and Android-developer-mode TTPs against Gmail and Korean-policy-expert targets.

The cluster's defender-relevant signature is espionage-primary, self-funding-secondary, with a credential-harvesting-and-volume-phishing operational style that produces a large but distributed crypto-theft surface rather than a small-N extraction surface. Defenders running G01-tuned controls (engineering-staff social-engineering training, supply-chain build attestation, multisig-vendor diligence) will not catch G07 activity unless those controls also extend to non-engineering staff (policy researchers, communications staff, executive assistants), Gmail / Chrome-extension hardening, and to cryptocurrency-wallet-software hardening on staff endpoints. The G01 / G07 boundary is operationally important precisely because it partitions the DPRK-attributed-crypto-theft attack surface into two distinct defender-control regimes; conflating the two — as some early industry reporting did before Mandiant's 2023 APT43 split — under-counts the policy-research and credential-harvesting attack surface and over-counts the engineering-supply-chain attack surface as fractions of the DPRK whole.

Targeting profile

OAK-G07's victim profile is espionage-target-led with cryptocurrency theft running as a parallel self-funding stream:

  • Foreign-policy and nuclear-policy experts — academic researchers, think-tank analysts, and former government officials working on Korean Peninsula, DPRK, sanctions-policy, and nuclear-non-proliferation issues; the canonical G07 target class per Mandiant, the BfV / NIS advisory, and Radio Free Asia reporting.
  • Journalists — particularly journalists covering DPRK affairs and inter-Korean policy; the cluster impersonates journalists and broadcast writers as a credential-harvesting persona, and also targets journalists directly.
  • Government bodies — Republic of Korea government, U.S. State Department, U.S. Department of Energy (historically named in the cluster's targeting set), Japanese government, European foreign ministries.
  • Defectors and human-rights organisations — North Korean defector communities and the NGOs that support them; a sustained G07 priority.
  • Cryptocurrency holders as a volume target — the cluster's phishing NFT campaigns, malicious-browser-extension deliveries, and post-2024 PowerShell / VBScript loaders targeting MetaMask and Trust Wallet wallet artifacts produce a distributed individual-victim cohort rather than a concentrated firm-victim cohort. This is the self-funding portion of the cluster's mission.
  • Cloud-mining and hash-rental service operators — not victims in the targeting sense but operational counterparties of the laundering pipeline; the Mandiant-documented hash-rental-and-cloud-mining technique runs through legitimate-or-quasi-legitimate cloud-mining services that may not know they are processing G07-attributed funds.

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; G07's intrusion surface (off-chain spear-phishing, credential harvesting, malicious browser-extensions, social-engineering rapport-building) sits outside that scope and is documented under external Group ID G0094. The on-chain Techniques observed in OAK-G07-attributable activity are concentrated on the laundering and off-ramp side of the cluster's self-funding pipeline:

  • OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader G07 laundering chain, consistent with the sector-wide DPRK pattern; the distinctive G07 laundering rail is hash-rental-and-cloud-mining rather than mixer-only routing.
  • OAK-T7.002 (CEX Deposit-Address Layering) — observed as the canonical off-ramp at the end of the hash-rental-and-cloud-mining laundering chain; mined-coin output is layered through CEX deposit-address activity into spendable fiat or operational-infrastructure procurement.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Chainalysis, TRM Labs, and Recorded Future to maintain G07-cluster identification across phishing-NFT contract rotations, across malicious-extension distribution rotations, and across the G01 / G07 sub-cluster boundary. Distinguishing G07 wallet activity from G01 wallet activity is a non-trivial defender problem precisely because both clusters share RGB substrate; T8.001 cluster-tracking is the canonical method for partitioning the two.
  • Pre-incident vectors not yet in OAK v0.1 scope (TAXONOMY-GAPS overlap with OAK-G01 and OAK-G04):
  • Spear-phishing with sustained social-engineering rapport-building under fabricated personas — the dominant G07 entry vector. Operators pose as journalists, broadcast writers, or subject-matter experts and build relationships with targets over weeks before delivering payloads.
  • Malicious browser-extensions and Android-app payloads — Chromium-extension Gmail exfiltration is a documented G07-distinctive TTP per the BfV / NIS advisory.
  • Phishing-NFT distribution at volume — Mandiant-documented >10 million phishing NFTs from June 2022 onward; structurally a credential-and-wallet-drain volume technique that does not fit cleanly under any single OAK v0.1 Tactic.
  • Hash-rental-and-cloud-mining laundering — the cluster-distinctive laundering rail; sits between OAK-T7 (laundering Tactic) and a future TAXONOMY-GAPS candidate for mining-as-laundering-conversion.

Observed Examples

No public incidents at v0.1 — worked examples pending per-incident forensic publication.

  • Mandiant APT43 report (March 28, 2023). The first comprehensive public characterisation of the cluster as APT43, including RGB attribution at moderate confidence, the hash-rental-and-cloud-mining laundering rail, the >10M phishing-NFT distribution, and the targeting profile across foreign-policy and nuclear research targets ([mandiantapt432023]). Attribution at confirmed (multi-vendor corroborated; subsequently affirmed by U.S. Treasury and ROK MOFA designations).
  • BfV / NIS joint cyber-security advisory (March 20, 2023). German federal counter-intelligence service and Republic of Korea NIS jointly published the operational write-up of the cluster's Chromium-extension and Android-developer-mode TTPs against Gmail and Korean-policy-expert targets ([bfvnis2023kimsuky]). Attribution at confirmed.
  • Republic of Korea MOFA Kimsuky designation (June 2, 2023). First-ever ROK sanctions designation of a DPRK hacking group, naming Kimsuky and citing the cluster's role in supporting DPRK weapons-programme intelligence collection ([mofakimsuky2023]). Attribution at confirmed.
  • U.S. Treasury OFAC Kimsuky SDN designation (November 30, 2023, Treasury press release JY1938). OFAC designation of Kimsuky as a DPRK cyber-espionage group subordinate to the RGB, alongside eight DPRK foreign-based agents (Kang Kyong Il, Ri Sung Il, Kang Phyong Guk, So Myong, Choe Un Hyok, Jang Myong Chol, Choe Song Chol, Im Song Sun), coordinated with Australia, Japan, and the ROK following the November 1, 2023 DPRK reconnaissance-satellite launch ([ofac2023kimsuky]). The U.S.-designation threshold event for the cluster. Attribution at confirmed.
  • Phishing-NFT volume campaigns (June 2022 onwards). Mandiant-tracked >10 million phishing NFTs delivered to cryptocurrency users across multiple blockchains as a credential-harvesting and wallet-drain volume technique. Attribution at inferred-strong per individual phishing-NFT contract; the cohort-level claim is documented in [mandiantapt432023].
  • MetaMask / Trust Wallet credential-harvesting campaigns (2024–2025). Multi-stage VBScript / PowerShell loaders with anti-VM checks and ZIP-compressed exfiltration of browser credentials and cryptocurrency-wallet artifacts (MetaMask, Trust Wallet); industry reporting attributes this to Kimsuky / G07 specifically. Attribution at inferred-strong.
  • Worked examples for specific G07-attributed cryptocurrency-theft incidents are pending v0.x and will live under examples/ once the per-incident G01 / G07 sub-cluster boundary stabilises sufficiently for the OAK confirmed / inferred-strong distinction to apply cleanly per case.

Citations

  • [mandiantapt432023] — Mandiant, "APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations," March 28, 2023; primary public-record characterisation of the cluster, RGB attribution, hash-rental-and-cloud-mining laundering rail, phishing-NFT volume.
  • [ofac2023kimsuky] — U.S. Department of the Treasury press release JY1938, November 30, 2023, designating Kimsuky and eight DPRK foreign-based agents.
  • [mofakimsuky2023] — Republic of Korea Ministry of Foreign Affairs designation of Kimsuky, June 2, 2023; first ROK sanctions action against a DPRK hacking group.
  • [bfvnis2023kimsuky] — Joint cyber-security advisory by the German Bundesamt für Verfassungsschutz (BfV) and the Republic of Korea National Intelligence Service (NIS), March 20, 2023; Chromium-extension and Android-app TTPs.
  • [chainalysis2024dprk] — DPRK-attributed crypto-theft scale companion citation (cited from G01 and G04 as well); aggregate DPRK volumes that the G01 / G04 / G07 partition jointly explains.

Discussion

On the attribution-strength split. The cluster-and-state-attribution layer (Kimsuky / APT43 = DPRK RGB) is confirmed — U.S. Treasury OFAC, Republic of Korea MOFA, German BfV, multiple national CERTs, external Group ID G0094, and a long multi-vendor industry-forensic record converge. The per-incident sub-cluster partition between G01 (APT38 / BlueNoroff) and G07 (APT43 / Kimsuky) within the broader DPRK / RGB whole is operationally meaningful but is inferred-strong in most cases rather than confirmed; the public record does not always cleanly resolve which RGB sub-element ran a given crypto-theft incident. OAK contributors writing G07-attributed examples should preserve this split per-incident: attributing a campaign to "DPRK / RGB" is confirmed-grade; attributing it specifically to G07 (vs G01) requires either explicit Mandiant / Microsoft / Google TAG / vendor naming or technical-fingerprint-led sub-cluster identification.

On why OAK-G07 is APT43 / Kimsuky rather than a sub-section of G01. Conflating G07 into G01 — i.e., treating "DPRK = Lazarus" — was the dominant industry framing pre-2023 and is what the Mandiant APT43 report explicitly broke. The two clusters share parent organisation (RGB), share state attribution, and intersect in the broader DPRK-attributed-crypto-theft volume aggregates reported by Chainalysis, but they have distinct operational ownership, distinct primary missions (espionage vs regime-revenue), distinct TTPs (spear-phishing vs supply-chain compromise), distinct targeting profiles (policy researchers vs crypto-firm engineers), and distinct downstream laundering signatures (hash-rental-and-cloud-mining vs bridge-and-mixer routing). Naming G07 as a separate Group reflects the post-2023 public-record reality and avoids the DPRK-monolith-fallacy that under-counts the policy-research and credential-harvesting attack surfaces.

On the relationship to OAK-G01. G01 (Lazarus / APT38 / BlueNoroff direct cyber attacks) and G07 (APT43 / Kimsuky espionage-and-self-funding) are sister clusters under shared state direction, not the same operator. Defenders running G01-tuned crypto-firm controls leave the G07 surface uncovered unless those controls extend to (a) non-engineering staff (policy, communications, executive), (b) Gmail / Chrome-extension hardening as a personal-account-and-corporate-account joint surface, (c) wallet-software-hardening on staff endpoints (MetaMask, Trust Wallet artifact protection), and (d) phishing-NFT awareness for any staff holding crypto in exposed wallets. The G01 / G07 separation in OAK is intended to make this control split explicit, parallel to the G01 / G04 separation that makes the engineering-pipeline / hiring-pipeline split explicit.

On the relationship to OAK-G04. G04 (DPRK IT-worker placement) and G07 (APT43 / Kimsuky) are also sister DPRK pipelines but operate under different parent structures (G04's worker-deployment infrastructure includes the Munitions Industry Department / Chinyong IT Cooperation Company stream alongside RGB-aligned activity; G07 is RGB-direct). The two intersect when a G04 placement enables a G07 espionage objective (insider access to policy-research targets), but the placement-vs-direct-attack split is operationally separable for defender controls and the two are correctly OAK Groups rather than a single combined entry.

On TAXONOMY-GAPS. OAK v0.1 does not yet have a Tactic for mining-as-laundering-conversion (the hash-rental-and-cloud-mining rail is the canonical case), nor for volume-distributed credential-and-wallet-drain phishing (the phishing-NFT rail is the canonical case). Both are G07-distinctive and are tracked here under "pre-incident vectors not yet in OAK v0.1 scope." A v0.x OAK update may introduce dedicated Tactics for both patterns; G07 will then anchor the worked examples.

On v0.x evolution. G07's 2026+ trajectory will depend on (a) whether the cluster's targeting profile drifts further toward direct cryptocurrency-theft volume (the 2024–2025 MetaMask / Trust Wallet credential-harvesting evolution is consistent with such drift) versus remaining espionage-primary with self-funding-secondary; (b) whether further OFAC and allied designations sustain the post-November-2023 enforcement tempo; (c) whether per-incident attribution between the G01 sub-cluster and the G07 sub-cluster becomes more cleanly resolvable as forensic providers refine sub-cluster fingerprints; and (d) whether any successor or splinter cluster is named publicly. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the DPRK-attributed cohort — additional named RGB or non-RGB cyber sub-elements — would each warrant their own OAK-Gnn entry rather than extension of G01 or G07, on the same per-cluster identity principle that motivated splitting G07 from G01 in the first place.

Software used