김수키(Kimsuky)만든 허위 권리보호 작성하신 게시물이 게시중단 되어 안내 말씀 드립니다.피싱 메일 분석(2025.4.1)

2025-06-16 Sakai Analysis of a Kimsuky Phishing Email Disguised as a False Rights Protection Notice for a Suspended Post (2025.4.1)

http://wezard4u.tistory.com/429512

Thumbnail for 김수키(Kimsuky)만든 허위 권리보호 작성하신 게시물이 게시중단 되어 안내 말씀 드립니다.피싱 메일 분석(2025.4.1)

Kimsuky is linked to a phishing email impersonating Naver's takedown-request service, telling the recipient that a blog post had been suspended for an alleged rights violation. The lure appears to target users writing about cryptocurrency by pushing them from a fake rights-protection notice toward a Naver-looking login flow with malicious redirection after authentication. The excerpt identifies invoicegroup.64bit.kr and IP address 158.247.242.169 as infrastructure associated by the author with APT43/Kimsuky. The activity matters because it uses familiar South Korean platform notifications and copyright/legal language to harvest credentials from crypto-adjacent victims.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://myblog.invoicegroup.64bi… 2025-06-16 2025-06-16
DOMAIN myblog.invoicegroup.64bit.kr 2025-06-16 2025-06-16
DOMAIN invoicegroup.64bit.kr 2025-06-16 2025-06-16
IPv4 158.247.242.169 2025-06-16 2025-06-16

Related Actors

Related Reports

« Back