김수키(Kimsuky) 해킹 주의! [국세청] 4월 신고·납부기한 변동통지서 도착-지금 확인하세요(2025.4.15)
2025-05-08 • Sakai • Beware of Kimsuky Hacking! [National Tax Service] April Filing and Payment Deadline Change Notice Has Arrived - Check Now (2025.4.15) •
Kimsuky activity used a phishing email impersonating South Korea's National Tax Service with an April filing and payment deadline notice as the lure. The message came through Mail.ru infrastructure and sent recipients to a spoofed Naver login flow on e-info.completeinfo.kro.kr, where the victim's Naver ID was prefilled and only the password was requested. The source highlights email authentication and header details, including ARC, SPF, DKIM, DMARC, and the Russian Mail.ru sending IP, to explain why the notice was suspicious. The campaign is framed as credential harvesting against Naver accounts rather than malware execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2025-05-08 | 2026-04-17 | |
| HASH | 0b554154078fdba15f0efe13c22ffea6 | 2025-05-08 | 2025-05-08 |
| HASH | 12073a6bae57349155e4c91e870a9b2… | 2025-05-08 | 2025-05-08 |
| HASH | f72c46652c56cf5afe7315198853ef3… | 2025-05-08 | 2025-05-08 |
| URL | http://e-info.completeinfo.kro.… | 2025-05-08 | 2025-05-08 |
| URL | http://e-info.completeinfo.kro.… | 2025-05-08 | 2025-05-08 |
| URL | http://e-info.completeinfo.kro.… | 2025-05-08 | 2025-05-08 |
| URL | http://e-info.completeinfo.kro.… | 2025-05-08 | 2025-05-08 |
| DOMAIN | e-info.completeinfo.kro.kr | 2025-05-08 | 2025-05-08 |
| IPv4 | 89.221.237.132 | 2025-05-08 | 2025-05-08 |