김수키(Kimsuky)에서 만든 세무통지서 피싱 메일 분석-[국세청] 5월 신고 납부기한 변동통지서가 도착했어요.(2025.5.20)

2025-05-28 Sakai Analysis of a Tax Notice Phishing Email Created by Kimsuky: [National Tax Service] May Filing and Payment Deadline Change Notice Has Arrived (2025.5.20)

https://wezard4u.tistory.com/429496

Thumbnail for 김수키(Kimsuky)에서 만든 세무통지서 피싱 메일 분석-[국세청] 5월 신고 납부기한 변동통지서가 도착했어요.(2025.5.20)

Kimsuky used a Korean National Tax Service-themed phishing email claiming that a May filing and payment deadline change notice was available for review. The lure targeted Naver users by pre-filling the victim email address and asking only for the password, then used doc-info.versioninfo.r-e.kr/nts links with parameters that imitated Naver login, privacy policy, legal notice, help, and company pages. The phishing flow stole Naver account credentials and redirected victims to legitimate Naver pages, making the activity harder for users to distinguish from a real electronic document notification. The message was sent from [email protected] via Mail.ru infrastructure, with sender IP 95.163.59.116 and SPF, DKIM, and DMARC passing.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-05-28 2026-04-17
DOMAIN inbox.ru 2024-12-02 2026-04-17
URL http://doc-info.versioninfo.r-e… 2025-05-28 2025-05-28
URL http://doc-info.versioninfo.r-e… 2025-05-28 2025-05-28
URL http://doc-info.versioninfo.r-e… 2025-05-28 2025-05-28
URL http://doc-info.versioninfo.r-e… 2025-05-28 2025-05-28
URL http://doc-info.versioninfo.r-e… 2025-05-28 2025-05-28
URL http://doc-info.versioninfo.r-e… 2025-05-28 2025-05-28
DOMAIN send277.i.mail.ru 2025-05-28 2025-05-28
DOMAIN doc-info.versioninfo.r-e.kr 2025-05-28 2025-05-28
IPv4 95.163.59.116 2025-05-28 2025-05-28

Related Actors

Related Reports

« Back