북한 해킹 조직 김수키(Kimsuky)에서 만든 연세 대학교 피싱 사이트-drive yonsei ackr(2024.9.10)
2024-09-17 • Sakai • Kimsuky phishing site impersonating Yonsei University drive •
The report describes a North Korea-linked Kimsuky phishing site apparently aimed at Yonsei University users. The observed infrastructure used a lookalike drive-themed URL under drive-yonsei-ac-kr.bit-albania.com and attempted to mimic a Chrome or Google sign-in flow. The evidence supports treating the activity as credential-phishing infrastructure rather than a generic university-themed page.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://drive-yonsei-ac-kr.bit-… | 2024-09-17 | 2024-09-17 |
| URL | https://protected-onlinestorage… | 2024-09-17 | 2024-09-17 |
| URL | https://protected-onlinestorage… | 2024-09-17 | 2024-09-17 |
| DOMAIN | protected-onlinestorage.store | 2024-09-17 | 2024-09-17 |
| DOMAIN | drive-yonsei-ac-kr.bit-albania.… | 2024-09-17 | 2024-09-17 |
Related Actors
Related Reports
Shares tags: Kimsuky, Phishing • Same author: Sakai • Published within a month
Shares tags: Kimsuky, Phishing • Same author: Sakai
2024-10-03 •
80% Match
#Cryptocurrency
#Kimsuky
#Phishing
#APT43
#Government
#Espionage
#Defense
#DarkPlum
Shares tags: Kimsuky, Phishing • Published within a month
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tags: Kimsuky, Phishing • Same author: Sakai
Shares tags: Kimsuky, Phishing • Same author: Sakai