The Kimsuky threat group, which is said to be backed by North Korea, has been active since 2013. Initial attacks on South Korea’s North Korea-related research institutes have been confirmed, followed by attacks on South Korea’s energy institutions in 2014 and attacks on other countries outside of South Korea since 2017. Spear phishing attacks are primarily aimed at stealing information and technology from organizations in the national defense, defense industry, media, diplomacy, state institutions, and academia.

