국세청 세무조사 출석요구 안내문 사칭 공격… 北 배후 추정
2023-01-17 • ESTSecurity • Tax investigation attendance notice impersonation attack suspected of North Korean backing •
ESRC reported a phishing campaign impersonating South Korea’s National Tax Service with emails titled as tax-investigation attendance notices and assessed the activity as suspected North Korean-backed. The lure targeted virtual-asset investors, spoofed the NTS sender address, and used a fake attached PDF area to redirect victims to a crafted Naver login phishing page for credential theft. After credential capture, the page displayed a legitimate-looking tax-investigation PDF to reduce victim suspicion. ESRC linked infrastructure such as navearcorps[.]help and 27.102.101[.]26 to earlier phishing domains, classified related activity as the Konni campaign, and noted ongoing investigation into links between Thallium/Kimsuky and Konni.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | goooglesecurity.com | 2022-10-25 | 2023-11-01 |
| DOMAIN | nidnaavers.com | 2023-01-17 | 2023-01-17 |
| DOMAIN | naaverascorp.com | 2023-01-17 | 2023-01-17 |
| DOMAIN | mybox-navers.com | 2023-01-17 | 2023-01-17 |
| DOMAIN | infonavera.com | 2023-01-17 | 2023-01-17 |
| IPv4 | 27.102.101.26 | 2023-01-17 | 2023-01-17 |