Kimsuky Operation Kabar Cobra

Kimsuky campaign targeting South Korean government using AppleSeed backdoor and FlowerPower malware.

Start date
1 February 2019
End date
Techniques
16

Attributed actors

Techniques (16)

collection2
T1114.001Local Email Collection
T1113Screen Capture
command-and-control2
T1105Ingress Tool Transfer
T1071.001Web Protocols
discovery2
T1082System Information Discovery
T1083File and Directory Discovery
execution3
T1059.003Windows Command Shell
T1059.001PowerShell
T1053.005Scheduled Task
exfiltration1
T1041Exfiltration Over C2 Channel
initial-access2
T1078Valid Accounts
T1566.001Spearphishing Attachment
persistence3
T1078Valid Accounts
T1547.001Registry Run Keys / Startup Folder
T1053.005Scheduled Task
privilege-escalation4
T1078Valid Accounts
T1547.001Registry Run Keys / Startup Folder
T1055Process Injection
T1053.005Scheduled Task
stealth4
T1078Valid Accounts
T1070.004File Deletion
T1055Process Injection
T1027Obfuscated Files or Information

Indicators of compromise

No IOCs linked to this campaign yet.

Kimsuky Operation Kabar Cobra — Campaign | Fancy Intel