북한 해킹 단체 김수키(Kimsuky) 한국 정부 및 군 기관 해킹 관련 APT Down: The North Korea Files 분석

2025-08-15 Sakai Analysis of APT Down: The North Korea Files related to hacking of South Korean government and military institutions by North Korean hacking group Kimsuky

https://wezard4u.tistory.com/429571

Thumbnail for 북한 해킹 단체 김수키(Kimsuky) 한국 정부 및 군 기관 해킹 관련 APT Down: The North Korea Files 분석

Leaked workstation and server material is presented as evidence of suspected Kimsuky activity against South Korean government, military, prosecution, foreign ministry, portal, media, and Taiwan-related targets. The excerpt describes spear-phishing infrastructure hosted on VPS systems, phishing administration tools such as generator.php and config.php, security-crawler IP blacklists, VPN use, AiTM-style phishing domains, and browser artifacts from Deepin Linux virtual machines. Tooling evidence includes a Tomcat kernel backdoor, custom Cobalt Strike beacon development, PowerShell reverse shells, an Onnara government-network module, RootRot/Ivanti-related client code, and Spawn Chimera port-knocking access logic for a South Korean newspaper IP. The material also reports GPKI certificate files, brute-force tooling for certificate passwords, and logs suggesting attempts to reach South Korean internal government systems, making the source relevant to tracking Kimsuky credential theft, phishing operations, and government-network access tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 203.234.192.200 2025-08-15 2025-09-22
DOMAIN nextforum-online.com 2025-08-15 2025-08-15
HASH 2bcef4444191c7a5943126338f8ba36… 2025-08-10 2025-08-15
HASH e6be345a13641b56da2a935eecfa7bd… 2025-08-10 2025-08-15

Related Actors

Related Reports

« Back