Kimsuky, also known by aliases such as Velvet Chollima, THALLIUM, and APT43, is a North Korean state-sponsored cyber espionage group attributed to the Reconnaissance General Bureau. This group has been active since at least 2012, primarily focusing on intelligence collection rather than financial gain, a characteristic that distinctly sets them apart from other North Korean threat actors like Lazarus Group. Their mission is to gather geopolitical, military, and foreign policy information to support Pyongyang's decision-making on issues related to the Korean Peninsula, nuclear policy, and sanctions. Kimsuky distinguishes itself through its methodical approach, combining tailored social engineering with modular malware frameworks, maintaining persistent access through obfuscation and anti-analysis techniques, and adapting quickly to bypass evolving security defenses. Notably, in 2023, Kimsuky was observed leveraging commercial large language models (LLMs) to enhance their vulnerability r