김수키(Kimsuky)에서 제작한 네이버 블로그 제한 안내 드립니다.피싱 메일 분석(2025.6.30)
2025-07-15 • Sakai • Analysis of a Phishing Email Created by Kimsuky Disguised as a Naver Blog Restriction Notice (2025.6.30) •
The Korean-language analysis attributes a Naver blog restriction phishing email to a North Korean hacking group and frames it as Kimsuky-related activity. The lure claimed the recipient's Naver blog posts would be excluded from search or deleted unless the user addressed supposed policy violations. Victims were sent to a fake login flow where the Naver ID was prefilled and only the password was requested, allowing the operator to steal both credentials. The body highlights a suspicious Russian sender address, an abnormal hcaredocs.o-r.kr domain, URL-encoded Naver login parameters, and redirect-style query strings designed to make the phishing page appear legitimate.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | inbox.ru | 2024-12-02 | 2026-04-17 |
| [email protected] | 2025-07-15 | 2025-07-15 | |
| DOMAIN | hcaredocs.o-r.kr | 2025-07-15 | 2025-07-15 |
| IPv4 | 95.163.59.12 | 2025-07-15 | 2025-07-15 |