김수키(Kimsuky)으로 추정이 되는 국민비서 경찰청 고지 안내 피싱 메일(2025.4.9)
2025-06-19 • Sakai • Cyber threat report on Kimsuky, Phishing •
The Korean analysis examines a phishing email suspected to be linked to Kimsuky that impersonates Naver’s electronic document service and a Korean National Police Agency notice. The message was sent from [email protected] through 89.221.237.155 in Moscow and directed recipients to p-doc.docpolice.p-e.kr, a domain unrelated to Naver. The lure embeds a legitimate Naver login URL inside a parameter to create redirection confusion, but the click path leads to a fake login page intended to steal Naver credentials. The recipient’s Naver address is included in the URL, indicating individualized targeting of Korean users rather than a generic mass-phishing link.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
| [email protected] | 2025-06-19 | 2025-06-19 | |
| DOMAIN | p-doc.docpolice.p-e.kr | 2025-06-19 | 2025-06-19 |
| IPv4 | 89.221.237.155 | 2025-06-19 | 2025-06-19 |