계정정보 탈취를 시도하는 피싱 공격 진행 중! 북 배후 추정

2025-01-24 ESTSecurity Ongoing Phishing Attacks Attempting Account Credential Theft, Suspected North Korean Involvement

https://blog.alyac.co.kr/5519

Thumbnail for 계정정보 탈취를 시도하는 피싱 공격 진행 중! 북 배후 추정

ESRC reports an active phishing campaign impersonating domestic portal customer-support notices, including takedown, account-change, and policy-violation themes. The emails contain buttons leading to attacker-controlled phishing pages that closely mimic legitimate login pages and may prefill victim account identifiers. The source assesses North Korean involvement as suspected, making the report relevant for defenders tracking credential-theft campaigns against Korean portal users and monitoring lookalike login infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN o-r.kr 2023-05-24 2026-06-01
DOMAIN r-e.kr 2023-03-23 2026-06-01
DOMAIN n-e.kr 2022-08-26 2026-06-01
DOMAIN p-e.kr 2021-12-21 2026-06-01

Related Actors

Related Reports

« Back