김수키(Kimsuky)에서 제작한 네이버 블로그 제한 안내 드립니다.피싱 메일 분석(2025.6.30)

2025-07-15 Sakai Analysis of a Phishing Email Created by Kimsuky Disguised as a Naver Blog Restriction Notice (2025.6.30)

https://wezard4u.tistory.com/429537

Thumbnail for 김수키(Kimsuky)에서 제작한 네이버 블로그 제한 안내 드립니다.피싱 메일 분석(2025.6.30)

The Korean-language analysis attributes a Naver blog restriction phishing email to a North Korean hacking group and frames it as Kimsuky-related activity. The lure claimed the recipient's Naver blog posts would be excluded from search or deleted unless the user addressed supposed policy violations. Victims were sent to a fake login flow where the Naver ID was prefilled and only the password was requested, allowing the operator to steal both credentials. The body highlights a suspicious Russian sender address, an abnormal hcaredocs.o-r.kr domain, URL-encoded Naver login parameters, and redirect-style query strings designed to make the phishing page appear legitimate.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN inbox.ru 2024-12-02 2026-04-17
EMAIL [email protected] 2025-07-15 2025-07-15
DOMAIN hcaredocs.o-r.kr 2025-07-15 2025-07-15
IPv4 95.163.59.12 2025-07-15 2025-07-15

Related Actors

Related Reports

« Back