김수키(Kimsuky)에서 만든 연세대학교 웹메일 피싱 사이트-rfa(.)lol/yonsei(2024.10.8)

2024-10-11 Sakai Yonsei University Webmail Phishing Site Created by Kimsuky (2024.10.8)

https://wezard4u.tistory.com/429299

Thumbnail for 김수키(Kimsuky)에서 만든 연세대학교 웹메일 피싱 사이트-rfa(.)lol/yonsei(2024.10.8)

The report documents a Kimsuky-attributed phishing site impersonating Yonsei University webmail at rfa.lol/yonsei, with visual elements and contact details intended to make the fake login page appear legitimate. Captured request details show submitted usernames and passwords being sent with standard form encoding, followed by scripted login-failure messaging to keep victims engaged. The campaign demonstrates credential-harvesting tradecraft against Korean academic or policy-adjacent targets and uses an RFA-themed domain path to add topical credibility.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 6.6.4.1 2024-10-08 2024-10-14
URL https://rfa.lol/yonsei 2024-10-11 2024-10-11
URL https://rfa.lol/yonsei/login.php 2024-10-11 2024-10-11
URL https://rfa.lol 2024-10-11 2024-10-11
IPv4 101.36.114.91 2024-10-11 2024-10-11

Related Actors

Related Reports

« Back