김수키(Kimsuky)에서 만든 피싱 메일-2024년 귀속 종합소득세 가산세 안내(2025.9.16)
2025-09-19 • Sakai • <map name="dGp?cmJzZGg="> •
The excerpt attributes a phishing email impersonating a Korean National Tax Service electronic document notice about 2024 comprehensive income tax surcharges to Kimsuky. The lure is image-based and hides recipient-specific link data inside Base64-encoded HTML map content rather than relying on an obvious attachment. Clicking the link redirects the recipient through firstlove-rose.com, which the author suggests may have been abused after the site became neglected or compromised. The message used the sender domain ntsdigital.xyz, Titan Mail/Zoho-based delivery infrastructure, and sending IP 154.90.62.226, showing tax-themed social engineering with personalized redirection infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://www.firstlove-rose.com/b… | 2025-09-19 | 2025-09-19 |
| URL | http://www.firstlove-rose.com/b… | 2025-09-19 | 2025-09-19 |
| DOMAIN | ntsdigital.xyz | 2025-09-19 | 2025-09-19 |
| IPv4 | 154.90.62.226 | 2025-09-19 | 2025-09-19 |