김수키(Kimsuky)에서 만든 피싱 메일-2024년 귀속 종합소득세 가산세 안내(2025.9.16)

2025-09-19 Sakai <map name="dGp?cmJzZGg=">

https://wezard4u.tistory.com/429601

Thumbnail for 김수키(Kimsuky)에서 만든 피싱 메일-2024년 귀속 종합소득세 가산세 안내(2025.9.16)

The excerpt attributes a phishing email impersonating a Korean National Tax Service electronic document notice about 2024 comprehensive income tax surcharges to Kimsuky. The lure is image-based and hides recipient-specific link data inside Base64-encoded HTML map content rather than relying on an obvious attachment. Clicking the link redirects the recipient through firstlove-rose.com, which the author suggests may have been abused after the site became neglected or compromised. The message used the sender domain ntsdigital.xyz, Titan Mail/Zoho-based delivery infrastructure, and sending IP 154.90.62.226, showing tax-themed social engineering with personalized redirection infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://www.firstlove-rose.com/b… 2025-09-19 2025-09-19
URL http://www.firstlove-rose.com/b… 2025-09-19 2025-09-19
DOMAIN ntsdigital.xyz 2025-09-19 2025-09-19
IPv4 154.90.62.226 2025-09-19 2025-09-19

Related Actors

Related Reports

« Back