국세청 세무조사 출석요구 안내문 사칭 공격… 北 배후 추정

2023-01-17 ESTSecurity Tax investigation attendance notice impersonation attack suspected of North Korean backing

https://blog.alyac.co.kr/5045

Thumbnail for 국세청 세무조사 출석요구 안내문 사칭 공격… 北 배후 추정

ESRC reported a phishing campaign impersonating South Korea’s National Tax Service with emails titled as tax-investigation attendance notices and assessed the activity as suspected North Korean-backed. The lure targeted virtual-asset investors, spoofed the NTS sender address, and used a fake attached PDF area to redirect victims to a crafted Naver login phishing page for credential theft. After credential capture, the page displayed a legitimate-looking tax-investigation PDF to reduce victim suspicion. ESRC linked infrastructure such as navearcorps[.]help and 27.102.101[.]26 to earlier phishing domains, classified related activity as the Konni campaign, and noted ongoing investigation into links between Thallium/Kimsuky and Konni.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN goooglesecurity.com 2022-10-25 2023-11-01
DOMAIN nidnaavers.com 2023-01-17 2023-01-17
DOMAIN naaverascorp.com 2023-01-17 2023-01-17
DOMAIN mybox-navers.com 2023-01-17 2023-01-17
DOMAIN infonavera.com 2023-01-17 2023-01-17
IPv4 27.102.101.26 2023-01-17 2023-01-17

Related Actors

Related Reports

« Back