탈륨(김수키)과 코니 APT 그룹의 연관관계 분석 Part3

2020-11-22 ESTSecurity Analysis of the relationship between thallium (Suki Kim) and Cony APT group Part 3

https://blog.alyac.co.kr/3390

Thumbnail for 탈륨(김수키)과 코니 APT 그룹의 연관관계 분석 Part3

ESRC’s Part 3 analysis connected Thallium/Kimsuky and Konni through shared or overlapping phishing infrastructure rather than treating them as separate unrelated clusters. The report examined a November 2020 Daum/Naver-themed credential-harvesting campaign using domains such as naver.midsecurity.org and 211.104.160.79, where directory exposure revealed additional phishing materials including Russian targets, OHCHR-themed lures, Summitz coin legal documents and Biden-era Korea strategy content. ESRC compared passive DNS, registrant emails and domains cited in Microsoft’s Thallium complaint, including rnaii.com, app-wallet.com and bigwnet.com, to show infrastructure links among Thallium, Kimsuky and Konni activity. The source emphasizes account-theft tradecraft, POP3/IMAP abuse for covert mail collection, and recurring Korean portal impersonation against North Korea-related and other Korean targets.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 52.177.14.24 2019-08-24 2025-07-01
DOMAIN noticeofpleadings.com 2020-11-22 2025-03-12
DOMAIN bigwnet.com 2019-09-02 2024-05-10
DOMAIN seoulhobi.biz 2019-08-24 2024-05-10
DOMAIN helpnaver.com 2019-08-29 2023-05-25
HASH 6bda04173d5f8491348e33cabc98f1b8 2020-11-22 2020-11-22
HASH 0ce1648ff7553189e5b5db2252e27fd5 2020-11-22 2020-11-22
EMAIL [email protected] 2020-11-22 2020-11-22
EMAIL [email protected] 2020-11-22 2020-11-22
EMAIL [email protected] 2020-11-22 2020-11-22
EMAIL [email protected] 2020-11-22 2020-11-22
EMAIL [email protected] 2020-11-22 2020-11-22
DOMAIN login.daum-protect.com 2020-11-22 2020-11-22
DOMAIN bignaver.com 2020-11-22 2020-11-22
DOMAIN un.midsecurity.org 2020-11-22 2020-11-22
DOMAIN cloudsecurityservice.net 2020-11-22 2020-11-22
DOMAIN midsecurity.org 2020-11-22 2020-11-22
DOMAIN dhfj.naverdns.co 2020-11-22 2020-11-22
DOMAIN daum.midsecurity.org 2020-11-22 2020-11-22
DOMAIN servicenidnaver.com 2020-11-22 2020-11-22
DOMAIN naver.midsecurity.org 2020-11-22 2020-11-22
DOMAIN cloudnaver.com 2020-11-22 2020-11-22
DOMAIN resetprofile.com 2020-11-22 2020-11-22
DOMAIN resetpolicy.com 2020-11-22 2020-11-22
DOMAIN netsecurityservice.com 2020-11-22 2020-11-22
DOMAIN nid.daum-protect.com 2020-11-22 2020-11-22
DOMAIN mail.resetpolicy.com 2020-11-22 2020-11-22
DOMAIN mail.servicenidnaver.com 2020-11-22 2020-11-22
DOMAIN daum.resetprofile.com 2020-11-22 2020-11-22
IPv4 211.104.160.84 2020-11-22 2020-11-22
IPv4 211.104.160.88 2020-11-22 2020-11-22
IPv4 211.104.160.79 2020-11-22 2020-11-22
IPv4 27.255.77.110 2020-11-22 2020-11-22
HASH 2487a29d1193b5f48d29df02804d8172 2019-12-23 2020-11-22
HASH 9e9745415793488ecf0774c7477bf2ae 2019-12-23 2020-11-22
IPv4 2.56.151.8 2019-12-23 2020-11-22
EMAIL [email protected] 2019-09-02 2020-11-22
EMAIL [email protected] 2019-08-29 2020-11-22
HASH 29506d03bf3f06df62089bed5af58906 2019-08-24 2020-11-22
HASH 9c025c3ff6ec04b7e67c9553ef4e2415 2019-08-24 2020-11-22
HASH c1063cfa402e64882d41f88ada87c8d1 2019-08-24 2020-11-22
HASH 8384803283c01a529eeaec8128e6a20a 2019-08-24 2020-11-22
HASH ff9f17fb1dd02186ba461586a1734212 2019-08-24 2020-11-22
HASH 6c290d6ddbe317844a4dccdc2259c6c1 2019-08-24 2020-11-22
HASH d503c3d182a632ac2c009c30e70951f2 2019-08-24 2020-11-22
EMAIL [email protected] 2019-08-24 2020-11-22
EMAIL [email protected] 2019-08-24 2020-11-22
EMAIL [email protected] 2019-08-24 2020-11-22
EMAIL [email protected] 2019-08-24 2020-11-22
DOMAIN rnaii.com 2019-08-24 2020-11-22
DOMAIN app-wallet.com 2019-08-24 2020-11-22
DOMAIN manage.app-wallet.com 2019-08-24 2020-11-22
DOMAIN rneail.com 2019-08-24 2020-11-22
IPv4 37.72.175.223 2019-08-24 2020-11-22
IPv4 27.255.79.205 2019-08-24 2020-11-22
IPv4 193.148.16.45 2019-08-24 2020-11-22
IPv4 91.235.116.144 2019-08-24 2020-11-22

Related Actors

Related Reports

« Back