김수키(Kimsuky) 해킹 주의! [국세청] 4월 신고·납부기한 변동통지서 도착-지금 확인하세요(2025.4.15)

2025-05-08 Sakai Beware of Kimsuky Hacking! [National Tax Service] April Filing and Payment Deadline Change Notice Has Arrived - Check Now (2025.4.15)

https://wezard4u.tistory.com/429480

Thumbnail for 김수키(Kimsuky) 해킹 주의! [국세청] 4월 신고·납부기한 변동통지서 도착-지금 확인하세요(2025.4.15)

Kimsuky activity used a phishing email impersonating South Korea's National Tax Service with an April filing and payment deadline notice as the lure. The message came through Mail.ru infrastructure and sent recipients to a spoofed Naver login flow on e-info.completeinfo.kro.kr, where the victim's Naver ID was prefilled and only the password was requested. The source highlights email authentication and header details, including ARC, SPF, DKIM, DMARC, and the Russian Mail.ru sending IP, to explain why the notice was suspicious. The campaign is framed as credential harvesting against Naver accounts rather than malware execution.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-05-08 2026-04-17
HASH 0b554154078fdba15f0efe13c22ffea6 2025-05-08 2025-05-08
HASH 12073a6bae57349155e4c91e870a9b2… 2025-05-08 2025-05-08
HASH f72c46652c56cf5afe7315198853ef3… 2025-05-08 2025-05-08
URL http://e-info.completeinfo.kro.… 2025-05-08 2025-05-08
URL http://e-info.completeinfo.kro.… 2025-05-08 2025-05-08
URL http://e-info.completeinfo.kro.… 2025-05-08 2025-05-08
URL http://e-info.completeinfo.kro.… 2025-05-08 2025-05-08
DOMAIN e-info.completeinfo.kro.kr 2025-05-08 2025-05-08
IPv4 89.221.237.132 2025-05-08 2025-05-08

Related Actors

Related Reports

« Back