계정정보 탈취를 시도하는 피싱 공격 진행 중! 북 배후 추정
2025-01-24 • ESTSecurity • Ongoing Phishing Attacks Attempting Account Credential Theft, Suspected North Korean Involvement •
ESRC reports an active phishing campaign impersonating domestic portal customer-support notices, including takedown, account-change, and policy-violation themes. The emails contain buttons leading to attacker-controlled phishing pages that closely mimic legitimate login pages and may prefill victim account identifiers. The source assesses North Korean involvement as suspected, making the report relevant for defenders tracking credential-theft campaigns against Korean portal users and monitoring lookalike login infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | o-r.kr | 2023-05-24 | 2026-06-01 |
| DOMAIN | r-e.kr | 2023-03-23 | 2026-06-01 |
| DOMAIN | n-e.kr | 2022-08-26 | 2026-06-01 |
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
Related Actors
Related Reports
Shares tags: Kimsuky, Phishing • Shares 3 IOCs
Shares tags: Kimsuky, Phishing • Shares 4 IOCs
Shares tags: Kimsuky, Phishing • Shares 4 IOCs
Shares tags: Kimsuky, Phishing • Shares 3 IOCs
Shares tag: Kimsuky • Shares 3 IOCs • Published within a month
Shares tag: Kimsuky • Shares 4 IOCs