Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
GroupKimsuky | Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`. |
| T1020 Automated Exfiltration |
GroupKimsuky | Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames. |
| T1027.012 LNK Icon Smuggling |
GroupKimsuky | Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script. |
| T1027.013 Encrypted/Encoded File |
GroupKimsuky | Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads. |
| T1033 System Owner/User Discovery |
GroupKimsuky | Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method. |
| T1055.001 Dynamic-link Library Injection |
GroupKimsuky | Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`. |
| T1056.001 Keylogging |
GroupKimsuky | Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory. |
| T1059.001 PowerShell |
GroupKimsuky | Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT. |
| T1059.003 Windows Command Shell |
GroupKimsuky | Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT. |
| T1059.005 Visual Basic |
GroupKimsuky | Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT. |
| T1070.004 File Deletion |
GroupKimsuky | Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files. |
| T1071.001 Web Protocols |
GroupKimsuky | Kimsuky has used HTTP GET and POST requests for C2. |
| T1074.001 Local Data Staging |
GroupKimsuky | Kimsuky has staged collected data files under |
| T1082 System Information Discovery |
GroupKimsuky | Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`. |
| T1083 File and Directory Discovery |
GroupKimsuky | Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways. |
| T1105 Ingress Tool Transfer |
GroupKimsuky | Kimsuky has downloaded additional scripts, tools, and malware onto victim systems. |
| T1106 Native API |
GroupKimsuky | Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts. |
| T1112 Modify Registry |
GroupKimsuky | Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck. |
| T1115 Clipboard Data |
GroupKimsuky | Kimsuky has the ability to steal data from the clipboard. |
| T1124 System Time Discovery |
GroupKimsuky | Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`. |
| T1140 Deobfuscate/Decode Files or Information |
GroupKimsuky | Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure. |
| T1217 Browser Information Discovery |
GroupKimsuky | Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys. |
| T1218.005 Mshta |
GroupKimsuky | Kimsuky has used mshta.exe to run malicious scripts on the system. |
| T1218.011 Rundll32 |
GroupKimsuky | Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network. |
| T1480.002 Mutual Exclusion |
GroupKimsuky | Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication. |
| T1489 Service Stop |
GroupKimsuky | Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox. |
| T1497.001 System Checks |
GroupKimsuky | Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`. |
| T1518.001 Security Software Discovery |
GroupKimsuky | Kimsuky has checked for the presence of antivirus software with |
| T1552.004 Private Keys |
GroupKimsuky | Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`. |
| T1559.001 Component Object Model |
GroupKimsuky | Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment. |
| T1560.001 Archive via Utility |
GroupKimsuky | Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration. |
| T1564.003 Hidden Window |
GroupKimsuky | Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows. |
| T1564.011 Ignore Process Interrupts |
GroupKimsuky | Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events. |
| T1678 Delay Execution |
GroupKimsuky | Kimsuky has utilized the Sleep function to ensure execution of scripts. |
| T1680 Local Storage Discovery |
GroupKimsuky | Kimsuky has enumerated drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.