김수키(Kimsuky)에서 만든 연세대학교 웹메일 피싱 사이트-rfa(.)lol/yonsei(2024.10.8)
2024-10-11 • Sakai • Yonsei University Webmail Phishing Site Created by Kimsuky (2024.10.8) •
The report documents a Kimsuky-attributed phishing site impersonating Yonsei University webmail at rfa.lol/yonsei, with visual elements and contact details intended to make the fake login page appear legitimate. Captured request details show submitted usernames and passwords being sent with standard form encoding, followed by scripted login-failure messaging to keep victims engaged. The campaign demonstrates credential-harvesting tradecraft against Korean academic or policy-adjacent targets and uses an RFA-themed domain path to add topical credibility.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 6.6.4.1 | 2024-10-08 | 2024-10-14 |
| URL | https://rfa.lol/yonsei | 2024-10-11 | 2024-10-11 |
| URL | https://rfa.lol/yonsei/login.php | 2024-10-11 | 2024-10-11 |
| URL | https://rfa.lol | 2024-10-11 | 2024-10-11 |
| IPv4 | 101.36.114.91 | 2024-10-11 | 2024-10-11 |
Related Actors
Related Reports
Shares tags: Kimsuky, Phishing • Same author: Sakai • Published within a month
Shares tags: Kimsuky, Phishing • Same author: Sakai
2024-10-03 •
80% Match
#Cryptocurrency
#Kimsuky
#Phishing
#APT43
#Government
#Espionage
#Defense
#DarkPlum
Shares tags: Kimsuky, Phishing • Published within a month
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tag: Kimsuky • Shares 1 IOC • Same author: Sakai • Published within a week