네이버 로그인화면으로 위장한 웹페이지

2023-02-02 Ahnlab Web page disguised as a Naver login page

https://asec.ahnlab.com/ko/46916/

Thumbnail for 네이버 로그인화면으로 위장한 웹페이지

AhnLab reports that infrastructure previously used for Kakao credential phishing was also hosting Naver login-themed phishing pages assessed from reverse-DNS, IP, domain, and related-file evidence as likely Kimsuky activity. The phishing pages imitated Naver password re-verification flows, prefilled target account identifiers, and mixed legitimate Naver links with attacker-controlled pages to reduce suspicion. The campaign appeared to abuse vulnerable websites built on the older Gnuboard 4 CMS to create domains and host the credential-harvesting pages. Representative indicators included accountskakao.bim-mgn[.]com, nid.bim-mgn[.]com, and wwwid.bim-mgn[.]com, and the article notes that target accounts changed over short intervals.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://nid.bim-mgn.com 2023-02-02 2023-02-13
URL http://wwwid.bim-mgn.com 2023-02-02 2023-02-13
URL http://accountskakao.bim-mgn.com 2023-02-02 2023-02-13
DOMAIN accountskakao.bim-mgn.com 2023-02-02 2023-02-13
DOMAIN wwwid.bim-mgn.com 2023-02-02 2023-02-13
DOMAIN nid.bim-mgn.com 2023-02-02 2023-02-13

Related Actors

Related Reports

« Back