카카오 로그인화면으로 위장한 웹페이지

2023-01-03 Ahnlab Webpage disguised as a Kakao login screen

https://asec.ahnlab.com/ko/45204/

Thumbnail for 카카오 로그인화면으로 위장한 웹페이지

AhnLab ASEC reported a credential-phishing page that closely imitated Kakao’s login screen and prefilled target account IDs. The suspected delivery route was phishing email, and ASEC inferred from the targeted IDs and its North Korea-related monitoring that the campaign likely focused on people or organizations connected to trade, media, or North Korea-related work. The malicious pages used lookalike accountskakao domains such as accountskakao.pnbbio[.]com and accountskakao.koreawus[.]com, then leaked entered IDs and passwords to attacker-controlled servers through GET requests. The report is relevant to DPRK-focused tracking as Korean-language social engineering against accounts likely used by journalists and North Korea-related personnel.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://accountskakao.koreawus.c… 2023-01-03 2023-01-10
URL http://accountskakao.pnbbio.com 2023-01-03 2023-01-10
DOMAIN accountskakao.pnbbio.com 2023-01-03 2023-01-10
DOMAIN accountskakao.koreawus.com 2023-01-03 2023-01-10

Related Reports

« Back