WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Joint Cybersecurity Advisory on North Korean APT Kimsuky
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory on North Korean APT Kimsuky

Author: Charles Egli

Created: Tuesday, October 27, 2020 - 18:34

Categories: Cybersecurity

Today the U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the U.S. Cyber Command published a joint cybersecurity advisory describing the tactics, techniques, and procedures used by the North Korean advanced persistent threat (APT) group Kimsuky. Some of the advisories key findings include that Kimsuky is most likely tasked by the North Korean regime with global intelligence gathering, including in the U.S.; that it employs social engineering tactics, spearphishing, and watering hole attacks to exfiltrate desired information from victims; and that it specifically targets individuals identified as experts in various fields. This advisory contains further technical details of this activity and offers indicators of compromise to help network administrators and defenders. To report activity related to information found in this advisory, contact the FBI via a local field office or via its 24/7 CyberWatch (CyWatch) at (855)292-3937 or Cy*****@*bi.gov. To request incident response resources or technical assistance related to these threats, contact CISA at ce*****@******hs.gov.

Attached Files:

TLP-WHITE_AA20-301A_North_Korean_APT_Focus_Kimsuky

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar