In the lead-up to APNIC60, where Chief Technical Officer Leslie Daigle will give a keynote address, we’re publishing a series of articles that address regionally meaningful threats beyond the well-documented Chinese-origin attacks. We present four distinct Asia-linked campaigns based on attacks seen directly in AIDE or confirmed by matching public reports. Each case offers a different lens on the threat landscape—ranging from geopolitical motivations to financial disruption and targeted espionage. Our goal is to provide context, elevate regional perspectives, and set the stage for deeper discussion during the keynote. This is the second article in the series; we previously examined Pakistani-based APT36.
Introduction
Kimsuky is widely assessed in open-source reporting, including by CISA and MITRE, to be associated with North Korean cyber espionage activity. Some threat intelligence sources characterize the group as state directed; however, this attribution is based on external analysis rather than direct confirmation by our research. Kimsuky has been reported to employ global intelligence collection techniques such as social engineering, spear phishing, and custom malware families including BabyShark and AppleSeed. The group is primarily targeting diplomats, researchers, and policy institutes in South Korea, Japan, and the United States.
To evaluate Kimsuky’s activity over a two-year window (January 2023–August 2025), we examined Asia-Pacific cyber activity patterns through the Global Cyber Alliance’s AIDE platform. AIDE began with SSH and Telnet based honeypots across 55 countries (~200 sensors). In November 2024, it transitioned to GCA-developed ProxyPot technology, now deployed in ~200 sensors across 25 countries and covering SSH, Telnet, FTP, SFTP, HTTP/HTTPS, and SMTP. This distributed network reveals that Kimsuky operates through a diverse global hosting footprint, using infrastructure services from cloud platforms, telecommunications providers, and Internet service providers worldwide to conduct reconnaissance operations targeting the Asia-Pacific region.
Our analysis shows sensors detecting suspicious activity aligned with known Kimsuky indicators of compromise (IoCs) and tactics, techniques, and procedures (TTPs), demonstrating the group’s sophisticated global reconnaissance operations.
AIDE’s Data Insights
User-Agent Signature Detection
One of the most significant findings in our analysis was the repeated appearance of a distinct Internet Explorer 11 (IE11) user-agent string in Command-and-Control (C2) traffic: “Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko.” This signature has been consistently documented in Kimsuky campaigns and serves as a reliable indicator for threat hunting operations. According to joint cybersecurity advisories from CISA, and FBI, this specific user-agent string is a well-established IoC for Kimsuky operations. The persistence of this legacy browser signature suggests the group continues to rely on established infrastructure patterns.

Geographic Distribution of Attack Infrastructure
AIDE sensors detected Kimsuky-attributed attacks originating from infrastructure hosted across multiple countries (economies), revealing the diverse global hosting footprint leveraged by this threat actor for reconnaissance operations (Figure 2).
The data demonstrates Kimsuky’s strategic use of global hosting infrastructure, with Panama-based services showing the highest volume of activity, followed by US-hosted infrastructure. While Asia-Pacific countries appear as attack sources, the substantial reliance on non-APAC infrastructure—particularly Panama, the US, UK, and Germany—indicates the group’s preference for using offshore hosting to obscure their operations and complicate attribution efforts.
This geographic distribution aligns with external reporting on Kimsuky’s 2024 “forceCopy” campaign, which noted their strategic use of offshore VPS nodes to evade takedowns.

Malware Activity Patterns
AIDE captured repeated login attempts tied to BabyShark and AppleSeed—malware families long associated with Kimsuky reconnaissance and persistence. Their presence across our sensors shows ongoing reliance on established toolchains and preparation for broader intrusions:
- “babyshark” login attempts — these align with patterns seen in the BabyShark script campaigns first observed in 2018, where a Windows script automates system profiling and credential theft.
- “appleseed” login attempts — these match naming conventions used by the AppleSeed backdoor family, which ASEC has tracked since 2019 for maintaining long-term access and exfiltration.
These repeated attempts to access systems using malware-related credentials suggest ongoing reconnaissance efforts and potential preparation for more extensive network intrusions.

Network Infrastructure Analysis
The AIDE dataset reveals Kimsuky operations spanning diverse network infrastructures, from one of the major telecommunications providers (258 hits, 26 unique IPs) to cloud service providers and various hosting providers across multiple continents. This aligns with SentinelOne’s reporting describing Kimsuky’s strategic use of diverse hosting infrastructure to evade detection.
Analysis of the ASN distribution shows the group’s preference for leveraging major Internet service providers and cloud platforms, consistent with their documented TTPs for blending malicious traffic with legitimate network communications.

Implications for Critical Infrastructure Protection and Global Reconnaissance Footprint
The broad nature of attacks detected in our AIDE dataset suggests Kimsuky’s reconnaissance extends beyond traditional espionage targets to include general network infrastructure assessment. This pattern is consistent with strategic objectives outlined in recent Department of Defense and FBI joint advisories regarding DPRK (Democratic People’s Republic of Korea) cyber activities.
The detection of systematic probing across diverse geographic regions and network types indicates potential preparation for larger-scale operations, highlighting the importance of robust network monitoring and threat intelligence sharing across international boundaries.

Figure 5: AIDE Reveals Global Reach of Suspicious Kimsuky Activity. AIDE detections map Kimsuky attack sources around the world, showing red arcs from attacker IPs to blue sensor IPs across every continent. This visual underscores the truly distributed hosting footprint leveraged for reconnaissance.

Conclusion
The data collected by AIDE’s global sensor network provides unprecedented visibility into Kimsuky’s reconnaissance operations. This threat group maintains a vast footprint across multiple continents, leveraging diverse network infrastructures and characteristic IoCs—such as distinctive IE11 user-agent signatures and malware-linked credential harvesting—to conduct its espionage campaigns. The geographic distribution of attacks and temporal correlation with known campaigns paint a comprehensive picture of ongoing, state-sponsored cyber reconnaissance.
These findings underscore the necessity of continuous monitoring and robust threat intelligence sharing to defend against persistent nation-state actors. No single organization can counter these sophisticated threats alone.
For Asia-Pacific operators, these findings highlight that today’s reconnaissance can become tomorrow’s disruption. Expanding sensing networks, sharing threat intelligence, and building resilient ecosystems together are critical steps to defend the infrastructure that underpins regional connectivity.
Collaborative defense strengthens early warning and response capabilities:
- Expand sensing networks: Broader participation in projects like AIDE amplifies visibility into hidden reconnaissance campaigns.
- Share threat intelligence: Cross-border exchange among operators, government, and research communities accelerates attribution and countermeasures.
- Build resilient ecosystems: Coordinated responses to offshore hosting abuse and distributed infrastructures are more effective than isolated blocking measures.
By sharing these insights and fostering collaboration, we enhance collective resilience against state-sponsored cyber espionage. If you would like to contribute to the AIDE research community or learn more about IoT security and threat detection, please contact us.
References
- CISA. North Korean Advanced Persistent Threat Focus: Kimsuky. CISA Advisory AA20-301A. https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a
- FBI, Department of State, NSA, National Intelligence Service, National Police Agency, Ministry of Foreign Affairs. North Korea Using Social Engineering to Enable Hacking of Think Tanks, Academia, and Media. Joint Cybersecurity Advisory. https://media.defense.gov/2023/Jun/01/2003234055/-1/-1/0/JOINT_CSA_DPRK_SOCIAL_ENGINEERING.PDF
- ASEC. Trend Analysis on Kimsuky Group’s Attacks Using AppleSeed. ASEC Analysis Report. https://asec.ahnlab.com/en/60054/
- MITRE ATT&CK®. Kimsuky – Group G0094. MITRE Corporation. https://attack.mitre.org/groups/G0094/
- SentinelOne Labs. Kimsuky Evolves Reconnaissance Capabilities in New Global Campaign. https://www.sentinelone.com/labs/kimsuky-evolves-reconnaissance-capabilities-in-new-global-campaign/
- Unit 42, Palo Alto Networks. New BabyShark Malware Targets U.S. National Security Think Tanks. https://unit42.paloaltonetworks.com/new-babyshark-malware-targets-u-s-national-security-think-tanks/
- FBI IC3. North Korean Actors Exploit Weak DMARC Security Policies to Mask Social Engineering Attempts. FBI Internet Crime Complaint Center Alert. https://www.ic3.gov/CSA/2024/240502.pdf
- The Hacker News. North Korean APT Kimsuky Uses LNK Files in “forceCopy” Campaign. https://thehackernews.com/2025/02/north-korean-apt-kimsuky-uses-lnk-files.html
- Zscaler Labs. Kimsuky Deploys TranslateXT to Target South Korean Academia. https://www.zscaler.com/blogs/security-research/kimsuky-deploys-translatext-target-south-korean-academia
- Cyfirma Research. From North Korean Phishing to Underground Online Hosting Services. https://www.cyfirma.com/research/from-north-korean-phishing-to-underground-online-hosting-services/
- Securonix Threat Research. New DeepGosu Attack Campaign. https://www.securonix.com/blog/securonix-threat-research-security-advisory-new-deepgosu-attack-campaign/

