북한 해킹 단체 김수키(Kimsuky) 한국 정부 및 군 기관 해킹 관련 APT Down: The North Korea Files 분석
2025-08-15 • Sakai • Analysis of APT Down: The North Korea Files related to hacking of South Korean government and military institutions by North Korean hacking group Kimsuky •
Leaked workstation and server material is presented as evidence of suspected Kimsuky activity against South Korean government, military, prosecution, foreign ministry, portal, media, and Taiwan-related targets. The excerpt describes spear-phishing infrastructure hosted on VPS systems, phishing administration tools such as generator.php and config.php, security-crawler IP blacklists, VPN use, AiTM-style phishing domains, and browser artifacts from Deepin Linux virtual machines. Tooling evidence includes a Tomcat kernel backdoor, custom Cobalt Strike beacon development, PowerShell reverse shells, an Onnara government-network module, RootRot/Ivanti-related client code, and Spawn Chimera port-knocking access logic for a South Korean newspaper IP. The material also reports GPKI certificate files, brute-force tooling for certificate passwords, and logs suggesting attempts to reach South Korean internal government systems, making the source relevant to tracking Kimsuky credential theft, phishing operations, and government-network access tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 203.234.192.200 | 2025-08-15 | 2025-09-22 |
| DOMAIN | nextforum-online.com | 2025-08-15 | 2025-08-15 |
| HASH | 2bcef4444191c7a5943126338f8ba36… | 2025-08-10 | 2025-08-15 |
| HASH | e6be345a13641b56da2a935eecfa7bd… | 2025-08-10 | 2025-08-15 |