APT-Q-2
2022-03-23 • Qianxin • Kimsuky(APT-Q-2)
APT-Q-2 is QiAnXin's internal tracking designation for Kimsuky, an espionage actor publicly disclosed in 2013 with activity traced to 2012. QiAnXin describes a primary focus on South Korea, especially defense, education, energy, government, healthcare, and think-tank targets, with confidential-information theft as the main objective. Its access methods include social engineering, spear-phishing, watering holes, and malicious tooling for Windows and Android. A 2024 campaign disguised data-stealing programs as legitimate South Korean software installers; the payload collected system, user, browser, file-transfer, secure-shell, document, and screenshot data, exfiltrated encrypted archives, and deleted itself to reduce traces. Later 2024 activity expanded toward European defense-sector personnel through fake recruitment documents. Those samples used script and executable droppers, encrypted configuration and command traffic, persistence through services or registry startup, file download, command execution, and rapid code changes, although QiAnXin kept that specific European attribution qualified.
-
43
Related Actors
-
799
Related Reports