김수키(Kimsuky)만든 허위 권리보호 작성하신 게시물이 게시중단 되어 안내 말씀 드립니다.피싱 메일 분석(2025.4.1)
2025-06-16 • Sakai • Analysis of a Kimsuky Phishing Email Disguised as a False Rights Protection Notice for a Suspended Post (2025.4.1) •
Kimsuky is linked to a phishing email impersonating Naver's takedown-request service, telling the recipient that a blog post had been suspended for an alleged rights violation. The lure appears to target users writing about cryptocurrency by pushing them from a fake rights-protection notice toward a Naver-looking login flow with malicious redirection after authentication. The excerpt identifies invoicegroup.64bit.kr and IP address 158.247.242.169 as infrastructure associated by the author with APT43/Kimsuky. The activity matters because it uses familiar South Korean platform notifications and copyright/legal language to harvest credentials from crypto-adjacent victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://myblog.invoicegroup.64bi… | 2025-06-16 | 2025-06-16 |
| DOMAIN | myblog.invoicegroup.64bit.kr | 2025-06-16 | 2025-06-16 |
| DOMAIN | invoicegroup.64bit.kr | 2025-06-16 | 2025-06-16 |
| IPv4 | 158.247.242.169 | 2025-06-16 | 2025-06-16 |