북한 김수키(Kimsuky)에서 만든 세무통지서 피싱 메일 분석-6월 신고 납부기한 통지서가 도착했어요.(2025.5.28)
2025-06-02 • Sakai • Analysis of a Tax Notice Phishing Email Created by North Korean Kimsuky: June Filing and Payment Deadline Notice Has Arrived (2025.5.28) •
Kimsuky is attributed to a Korean-language phishing email impersonating a National Tax Service notice about a June filing and payment deadline. The lure sends victims to hxxp://nts(.)authenticatesvc(.)kro(.)kr/nts/ with parameters that mimic a Naver login flow and prefill the victim’s email address through values such as wreply, m, rv, and ru. The phishing site captures Naver account credentials, including the submitted password and email address, exposing victims to follow-on account compromise and cryptocurrency or other secondary fraud. The infrastructure resolves to 158(.)247(.)247(.)157 on Vultr in Seoul and shows directories such as help.php, invoice, nts, and send_new, while mail headers reference invoicdev(.)64bit(.)kr and Zoho relay paths used to make delivery appear more legitimate.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | o-r.kr | 2023-05-24 | 2026-06-01 |
| DOMAIN | n-e.kr | 2022-08-26 | 2026-06-01 |
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
| IPv4 | 158.247.247.157 | 2025-06-02 | 2025-06-17 |
| URL | http://nts.authenticatesvc.kro.… | 2025-06-02 | 2025-06-02 |
| DOMAIN | bounce-zem.invoicdev.64bit.kr | 2025-06-02 | 2025-06-02 |
| DOMAIN | zohomail360.com | 2025-06-02 | 2025-06-02 |
| DOMAIN | invoicdev.64bit.kr | 2025-06-02 | 2025-06-02 |
| DOMAIN | nts.authenticatesvc.kro.kr | 2025-06-02 | 2025-06-02 |
| DOMAIN | 40naver.com | 2025-06-02 | 2025-06-02 |
| DOMAIN | mx.us.zohomail360.com | 2025-06-02 | 2025-06-02 |
| DOMAIN | us.zohomail360.com | 2025-06-02 | 2025-06-02 |
| IPv4 | 136.143.188.154 | 2025-06-02 | 2025-06-02 |