위협 행위자 김수키의 이메일 피싱 캠페인 분석

2024-12-02 Genians Analysis of Kimsuky Email Phishing Campaign

https://www.genians.co.kr/blog/threat_intelligence/kimsuky-cases

Thumbnail for 위협 행위자 김수키의 이메일 피싱 캠페인 분석

Genians links a multi-year email phishing campaign to Kimsuky, targeting North Korea researchers and related organizations in South Korea with account-theft lures rather than malware attachments. The activity impersonated familiar public-sector, portal, cloud, and financial electronic-document notices, including National Secretary, Naver MYBOX, tax, pension, and banking themes. Operators used Japanese and Korean mail services early on, then shifted to forged and real Russian sender domains while continuing to abuse Korean free-domain services and phishing sites hosted on infrastructure such as 185.27.134.x and 185.105.33.106. The report also ties the campaign to the exposed “star 3.0” mailer on evangelia.edu, a site previously associated with Kimsuky tooling and a macro document that launched mshta against an evangelia.edu HTA payload. The findings matter because malwareless credential phishing can enable mailbox surveillance and follow-on intrusions against policy, research, and institutional targets.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN o-r.kr 2023-05-24 2026-06-01
DOMAIN r-e.kr 2023-03-23 2026-06-01
DOMAIN n-e.kr 2022-08-26 2026-06-01
DOMAIN p-e.kr 2021-12-21 2026-06-01
DOMAIN internet.ru 2024-12-02 2026-04-17
DOMAIN inbox.ru 2024-12-02 2026-04-17
HASH d8249f33e07479ce9c0e44be73d3deac 2024-12-02 2024-12-04
HASH 6ead104743be6575e767986a71cf4bd9 2024-12-02 2024-12-04
HASH adb30d4dd9e1bbe82392b4c01f561e46 2024-12-02 2024-12-04
HASH ab75a54c3d6ed01ba9478d9fecd443af 2024-12-02 2024-12-04
HASH 658a8856d48aabc0ecfeb685d836621b 2024-12-02 2024-12-04
HASH a75196b7629e3af03056c75af37f37cf 2024-12-02 2024-12-04
HASH aa41e4883a9c5c91cdab225a0e82d86a 2024-12-02 2024-12-04
HASH b591cbd3f585dbb1b55f243d5a5982bc 2024-12-02 2024-12-04
HASH 3cd67d99bcc8f3b959c255c9e8702e9f 2024-12-02 2024-12-04
HASH 0def51118a28987a929ba26c7413da29 2024-12-02 2024-12-04
HASH a6588c10d9c4c2b3837cd7ce6c43f72e 2024-12-02 2024-12-04
HASH 2ff911b042e5d94dd78f744109851326 2024-12-02 2024-12-04
DOMAIN ncloud.ru 2024-12-02 2024-12-04
DOMAIN mmbox.ru 2024-12-02 2024-12-04
IPv4 185.27.134.144 2024-12-02 2024-12-04
IPv4 185.27.134.140 2024-12-02 2024-12-04
IPv4 185.27.134.201 2024-12-02 2024-12-04
IPv4 185.27.134.93 2024-12-02 2024-12-04
IPv4 185.105.33.106 2024-12-02 2024-12-04
IPv4 185.27.134.120 2024-12-02 2024-12-04
URL https://evangelia.edu/image/bin… 2024-12-02 2024-12-02
DOMAIN wud.wuaze.com 2024-12-02 2024-12-02
DOMAIN biglobe.ne.jp 2024-12-02 2024-12-02
DOMAIN covd.2kool4u.net 2024-12-02 2024-12-02
DOMAIN owna.loveslife.biz 2024-12-02 2024-12-02
DOMAIN ned.kesug.com 2024-12-02 2024-12-02
DOMAIN nidiogln.n-e.kr 2024-12-02 2024-12-02
DOMAIN cookiemanager.n-e.kr 2024-12-02 2024-12-02
DOMAIN naverbox.p-e.kr 2024-12-01 2024-12-02
HASH 7ca1a603a7440f1031c666afbe44afc8 2019-09-02 2024-12-02

Related Actors

Related Reports

« Back