북한 김수키(Kimsuky)에서 만든 세무통지서 피싱 메일 분석-6월 신고 납부기한 통지서가 도착했어요.(2025.5.28)

2025-06-02 Sakai Analysis of a Tax Notice Phishing Email Created by North Korean Kimsuky: June Filing and Payment Deadline Notice Has Arrived (2025.5.28)

https://wezard4u.tistory.com/429501

Thumbnail for 북한 김수키(Kimsuky)에서 만든 세무통지서 피싱 메일 분석-6월 신고 납부기한 통지서가 도착했어요.(2025.5.28)

Kimsuky is attributed to a Korean-language phishing email impersonating a National Tax Service notice about a June filing and payment deadline. The lure sends victims to hxxp://nts(.)authenticatesvc(.)kro(.)kr/nts/ with parameters that mimic a Naver login flow and prefill the victim’s email address through values such as wreply, m, rv, and ru. The phishing site captures Naver account credentials, including the submitted password and email address, exposing victims to follow-on account compromise and cryptocurrency or other secondary fraud. The infrastructure resolves to 158(.)247(.)247(.)157 on Vultr in Seoul and shows directories such as help.php, invoice, nts, and send_new, while mail headers reference invoicdev(.)64bit(.)kr and Zoho relay paths used to make delivery appear more legitimate.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN o-r.kr 2023-05-24 2026-06-01
DOMAIN n-e.kr 2022-08-26 2026-06-01
DOMAIN p-e.kr 2021-12-21 2026-06-01
IPv4 158.247.247.157 2025-06-02 2025-06-17
URL http://nts.authenticatesvc.kro.… 2025-06-02 2025-06-02
DOMAIN bounce-zem.invoicdev.64bit.kr 2025-06-02 2025-06-02
DOMAIN zohomail360.com 2025-06-02 2025-06-02
DOMAIN invoicdev.64bit.kr 2025-06-02 2025-06-02
DOMAIN nts.authenticatesvc.kro.kr 2025-06-02 2025-06-02
DOMAIN 40naver.com 2025-06-02 2025-06-02
DOMAIN mx.us.zohomail360.com 2025-06-02 2025-06-02
DOMAIN us.zohomail360.com 2025-06-02 2025-06-02
IPv4 136.143.188.154 2025-06-02 2025-06-02

Related Actors

Related Reports

« Back