ATT&CKReferencesAryaka Kimsuky July 2025

Aryaka Kimsuky July 2025

Varadharajan Krishnasamy, Aditya K Sood. (2025, July 29). From Reconnaissance to Control: The Operational Blueprint of Kimsuky APT for Cyber Espionage. Retrieved April 18, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples35

TechniqueUsed byProcedure example
T1005
Data from Local System
GroupKimsuky

Kimsuky has collected Office, PDF, and HWP documents from its victims. Kimsuky has also harvested victim files through the use of the `RecentFiles()` function that collects paths of recently accessed files by parsing .lnk shortcuts from `%APPDATA%\Microsoft\Windows\Recent`.

T1020
Automated Exfiltration
GroupKimsuky

Kimsuky has exfiltrated data to C2 servers using an automated script that executes every 10 minutes and after successful checks for the presence of pre-designated staged filenames.

T1027.012
LNK Icon Smuggling
GroupKimsuky

Kimsuky has used the LNK icon location to execute malicious scripts. Kimsuky has also padded the LNK target field properties with extra spaces to obscure the script.

T1027.013
Encrypted/Encoded File
GroupKimsuky

Kimsuky has obfuscated code within files by converting hexadecimal strings to decimal numbers using the `CLng function` in combination with processing arithmetic operations and leveraging the `Chr function` to generate readable characters. Kimsuky has also encoded files with Base64 and RC4. Kimsuky has utilized XOR and RC4 to encode malicious payloads.

T1033
System Owner/User Discovery
GroupKimsuky

Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method.

T1055.001
Dynamic-link Library Injection
GroupKimsuky

Kimsuky has the ability to load DLLs via reflective injection by allocating memory using `VirtualAllocEx()`, then decrypting a DLL with `WriteProcessMemory()` and invoking execution through `CreateRemoteThread()`.

T1056.001
Keylogging
GroupKimsuky

Kimsuky has used a PowerShell-based keylogger as well as a tool called MECHANICAL to log keystrokes. Kimsuky has also leveraged Native Windows API functions such as `GetAsyncKeyState()` along with others to capture keystrokes every 50 milliseconds and stores data in a file stored in the temp directory.

T1059.001
PowerShell
GroupKimsuky

Kimsuky has executed a variety of PowerShell scripts including Invoke-Mimikatz. Kimsuky has also utilized PowerShell scripts for execution, persistence, and defense evasion. Kimsuky has leveraged PowerShell’s cmdlet `Expand-Archive` to extract contents of zip files into the same directory. Kimsuky has employed ClickFix type tactics enticing victims to copy and paste malicious PowerShell commands and scripts, where the scripts ultimately led to QuasarRAT.

T1059.003
Windows Command Shell
GroupKimsuky

Kimsuky has executed Windows commands by using `cmd` and running batch scripts. Kimsuky has also used `cmd.exe` to automatically open downloaded decoy pdf documents with the system’s default PDF viewer. Kimsuky has utilized malicious payloads to create reverse shells within the victim environment. Kimsuky has also used batch scripts to eventually run QuasarRAT.

T1059.005
Visual Basic
GroupKimsuky

Kimsuky has used Visual Basic to download malicious payloads. Kimsuky has also used malicious VBA macros within maldocs disguised as forms that trigger when a victim types any content into the lure. Kimsuky has also leveraged VBScript (VBS) scripts to execute temp.vbs every 19 minutes using a scheduled task to run QuasarRAT.

T1070.004
File Deletion
GroupKimsuky

Kimsuky has deleted the exfiltrated data on disk after transmission. Kimsuky has also used an instrumentor script to terminate browser processes running on an infected system and then delete the cookie files on disk. Kimsuky has deleted files using the `Remove-Item` PowerShell commandlet to remove traces of executed payloads. Kimsuky has also removed remnants of files used for delivery to include .log and .zip files.

T1071.001
Web Protocols
GroupKimsuky

Kimsuky has used HTTP GET and POST requests for C2.

T1074.001
Local Data Staging
GroupKimsuky

Kimsuky has staged collected data files under C:\Program Files\Common Files\System\Ole DB\. Kimsuky has also gathered data in structured directories prior to exfiltration under the %TEMP% environment variable.

T1082
System Information Discovery
GroupKimsuky

Kimsuky has enumerated OS type, OS version, and other information using a script or the "systeminfo" command. Kimsuky has also obtained system information such as OS type, OS version, and system type through querying various Windows Management Instrumentation (WMI) classes including `Win32_OperatingSystem`.

T1083
File and Directory Discovery
GroupKimsuky

Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways.

T1105
Ingress Tool Transfer
GroupKimsuky

Kimsuky has downloaded additional scripts, tools, and malware onto victim systems.

T1106
Native API
GroupKimsuky

Kimsuky has utilized Native APIs to collect data from victim hosts and facilitate execution of malicious scripts.

T1112
Modify Registry
GroupKimsuky

Kimsuky has modified Registry settings for default file associations to enable all macros and for persistence. Kimsuky has also modified the registry entry for `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` registry key for persistence with the name WindowsSecurityCheck.

T1115
Clipboard Data
GroupKimsuky

Kimsuky has the ability to steal data from the clipboard.

T1124
System Time Discovery
GroupKimsuky

Kimsuky has gathered the system time of the device using the PowerShell cmdlet `Get-Date`.

T1140
Deobfuscate/Decode Files or Information
GroupKimsuky

Kimsuky has decoded malicious VBScripts using Base64. Kimsuky has also decoded malicious PowerShell scripts using Base64. Kimsuky has decoded RC4 obfuscated files prior to downloading files from their infrastructure.

T1217
Browser Information Discovery
GroupKimsuky

Kimsuky has collected sensitive browser data using the function `GetBrowserData()` to include login credentials, bookmarks, cookies, and encryption keys.

T1218.005
Mshta
GroupKimsuky

Kimsuky has used mshta.exe to run malicious scripts on the system.

T1218.011
Rundll32
GroupKimsuky

Kimsuky has used `rundll32.exe` to execute malicious scripts and malware on a victim's network.

T1480.002
Mutual Exclusion
GroupKimsuky

Kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host. Kimsuky has leveraged PowerShell to store the Process ID (PID) of the currently running malicious PowerShell script into a file named pid.txt which is saved locally on the victim host in the %TEMP% Directory and is queried prior to execution of subsequent PowerShell script to prevent duplication.

T1489
Service Stop
GroupKimsuky

Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox.

T1497.001
System Checks
GroupKimsuky

Kimsuky has detected and killed virtual environments by using the PowerShell cmdlet `Get-CimInstance` that searches the classname of the computer system manufacturer through an if statement of `if($computerSystem.Manufacturer -match "VMware" -or $computerSystem.Manufacturer -match "Microsoft" -or $computerSystem.Manufacturer -match "VirtualBox")`.

T1518.001
Security Software Discovery
GroupKimsuky

Kimsuky has checked for the presence of antivirus software with powershell Get-CimInstance -Namespace root/securityCenter2 – classname antivirusproduct. Kimsuky has also obtained details on antivirus software through WMI queries using `Win32_OperatingSystem` and `SecurityCenter2.AntiVirusProduct`. Kimsuky has also checked the status of Windows Defender through the use `cmd /s sc query WinDefend`.

T1552.004
Private Keys
GroupKimsuky

Kimsuky has accessed a Local State files associated with Chromium-based browsers that contain the AES key used to encrypt passwords stored in the browser to include `app_bound_encrypted_key`.

T1559.001
Component Object Model
GroupKimsuky

Kimsuky has leveraged Component Object Model (COM) to create scheduled tasks to include using naming conventions that mimic legitimate applications. Kimsuky has leveraged obfuscation VBScript to form a string in `WScript.Shell` which has downloaded a malicious payload to the victim environment.

T1560.001
Archive via Utility
GroupKimsuky

Kimsuky has used QuickZip to archive stolen files before exfiltration. Kimsuky has used the Send() function to compress all collected data into a zip file named init,.zip, then renames it to init.dat, before exfiltration.

T1564.003
Hidden Window
GroupKimsuky

Kimsuky has used an information gathering module that will hide an AV software window from the victim. Kimsuky has also been known to use `-WindowStyle Hidden` to conceal PowerShell windows.

T1564.011
Ignore Process Interrupts
GroupKimsuky

Kimsuky has leveraged the PowerShell `-ErrorAction SilentlyContinue` command to continue execution through system events.

T1678
Delay Execution
GroupKimsuky

Kimsuky has utilized the Sleep function to ensure execution of scripts.

T1680
Local Storage Discovery
GroupKimsuky

Kimsuky has enumerated drives.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.