방첩사 계엄 문건 사칭 전자우편은 북 소행
2025-04-16 • KRNPA • Cyber threat report on News, Phishing •
Attachments
South Korea's National Police Agency reported that emails sent in December 2024 impersonating the release of a Defense Counterintelligence Command martial-law document were determined to be North Korean activity. Investigators said the broader campaign sent 126,266 spoofed emails to 17,744 people between November 2024 and January 2025 to steal personal information and account credentials. The targets included people working in unification, security, defense, and foreign affairs, while the infrastructure reused servers linked to prior North Korea-related cases and contained collected information on defectors and military topics. The emails used government-like or acquaintance-like sender addresses and redirected victims to phishing pages that requested portal-site usernames and passwords.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | co.kro.kr | 2025-04-16 | 2025-04-16 |
| DOMAIN | kakao-auth.com | 2025-03-04 | 2025-04-16 |
| DOMAIN | naver-auth.com | 2025-03-04 | 2025-04-16 |
| DOMAIN | googlauth.com | 2025-03-04 | 2025-04-16 |