위협 행위자 김수키의 이메일 피싱 캠페인 분석
2024-12-02 • Genians • Analysis of Kimsuky Email Phishing Campaign •
https://www.genians.co.kr/blog/threat_intelligence/kimsuky-cases
Genians links a multi-year email phishing campaign to Kimsuky, targeting North Korea researchers and related organizations in South Korea with account-theft lures rather than malware attachments. The activity impersonated familiar public-sector, portal, cloud, and financial electronic-document notices, including National Secretary, Naver MYBOX, tax, pension, and banking themes. Operators used Japanese and Korean mail services early on, then shifted to forged and real Russian sender domains while continuing to abuse Korean free-domain services and phishing sites hosted on infrastructure such as 185.27.134.x and 185.105.33.106. The report also ties the campaign to the exposed “star 3.0” mailer on evangelia.edu, a site previously associated with Kimsuky tooling and a macro document that launched mshta against an evangelia.edu HTA payload. The findings matter because malwareless credential phishing can enable mailbox surveillance and follow-on intrusions against policy, research, and institutional targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | o-r.kr | 2023-05-24 | 2026-06-01 |
| DOMAIN | r-e.kr | 2023-03-23 | 2026-06-01 |
| DOMAIN | n-e.kr | 2022-08-26 | 2026-06-01 |
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
| DOMAIN | internet.ru | 2024-12-02 | 2026-04-17 |
| DOMAIN | inbox.ru | 2024-12-02 | 2026-04-17 |
| HASH | d8249f33e07479ce9c0e44be73d3deac | 2024-12-02 | 2024-12-04 |
| HASH | 6ead104743be6575e767986a71cf4bd9 | 2024-12-02 | 2024-12-04 |
| HASH | adb30d4dd9e1bbe82392b4c01f561e46 | 2024-12-02 | 2024-12-04 |
| HASH | ab75a54c3d6ed01ba9478d9fecd443af | 2024-12-02 | 2024-12-04 |
| HASH | 658a8856d48aabc0ecfeb685d836621b | 2024-12-02 | 2024-12-04 |
| HASH | a75196b7629e3af03056c75af37f37cf | 2024-12-02 | 2024-12-04 |
| HASH | aa41e4883a9c5c91cdab225a0e82d86a | 2024-12-02 | 2024-12-04 |
| HASH | b591cbd3f585dbb1b55f243d5a5982bc | 2024-12-02 | 2024-12-04 |
| HASH | 3cd67d99bcc8f3b959c255c9e8702e9f | 2024-12-02 | 2024-12-04 |
| HASH | 0def51118a28987a929ba26c7413da29 | 2024-12-02 | 2024-12-04 |
| HASH | a6588c10d9c4c2b3837cd7ce6c43f72e | 2024-12-02 | 2024-12-04 |
| HASH | 2ff911b042e5d94dd78f744109851326 | 2024-12-02 | 2024-12-04 |
| DOMAIN | ncloud.ru | 2024-12-02 | 2024-12-04 |
| DOMAIN | mmbox.ru | 2024-12-02 | 2024-12-04 |
| IPv4 | 185.27.134.144 | 2024-12-02 | 2024-12-04 |
| IPv4 | 185.27.134.140 | 2024-12-02 | 2024-12-04 |
| IPv4 | 185.27.134.201 | 2024-12-02 | 2024-12-04 |
| IPv4 | 185.27.134.93 | 2024-12-02 | 2024-12-04 |
| IPv4 | 185.105.33.106 | 2024-12-02 | 2024-12-04 |
| IPv4 | 185.27.134.120 | 2024-12-02 | 2024-12-04 |
| URL | https://evangelia.edu/image/bin… | 2024-12-02 | 2024-12-02 |
| DOMAIN | wud.wuaze.com | 2024-12-02 | 2024-12-02 |
| DOMAIN | biglobe.ne.jp | 2024-12-02 | 2024-12-02 |
| DOMAIN | covd.2kool4u.net | 2024-12-02 | 2024-12-02 |
| DOMAIN | owna.loveslife.biz | 2024-12-02 | 2024-12-02 |
| DOMAIN | ned.kesug.com | 2024-12-02 | 2024-12-02 |
| DOMAIN | nidiogln.n-e.kr | 2024-12-02 | 2024-12-02 |
| DOMAIN | cookiemanager.n-e.kr | 2024-12-02 | 2024-12-02 |
| DOMAIN | naverbox.p-e.kr | 2024-12-01 | 2024-12-02 |
| HASH | 7ca1a603a7440f1031c666afbe44afc8 | 2019-09-02 | 2024-12-02 |