김수키(Kimsuky)로 추정이 되는 카카오 고객센터 피싱 메일(2024.12.16)
2025-01-31 • Sakai • Likely Kimsuky Kakao Customer Center Phishing Email •
The report analyzes a phishing email attributed as likely Kimsuky that impersonates Kakao customer support and warns recipients that an account will become dormant. It identifies suspicious sender infrastructure, mismatched Kakao branding, and mail-header details that differ from legitimate Kakao service messages. The activity fits credential-theft tradecraft against Korean users and provides defenders with sender, IP, and lure details for email filtering and user-awareness controls.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7737f0cc2c82cce3d45aeb0cbecd898c | 2025-01-31 | 2025-01-31 |
| HASH | e398a530b742a7e9e2314f5e8527805… | 2025-01-31 | 2025-01-31 |
| [email protected] | 2025-01-31 | 2025-01-31 | |
| DOMAIN | uws64-180.cafe24.com | 2025-01-31 | 2025-01-31 |
| DOMAIN | jad.co.kr | 2025-01-31 | 2025-01-31 |
| DOMAIN | kaka.net | 2025-01-31 | 2025-01-31 |
| IPv4 | 183.111.174.84 | 2025-01-31 | 2025-01-31 |
Related Actors
Related Reports
Shares tags: Kimsuky, Phishing • Same author: Sakai • Published within a week
Shares tags: Kimsuky, Phishing • Published within a month
Shares tags: Kimsuky, Phishing • Published within a week
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tags: Kimsuky, Phishing • Same author: Sakai