탈륨(김수키)과 코니 APT 그룹의 연관관계 분석 Part3
2020-11-22 • ESTSecurity • Analysis of the relationship between thallium (Suki Kim) and Cony APT group Part 3 •
ESRC’s Part 3 analysis connected Thallium/Kimsuky and Konni through shared or overlapping phishing infrastructure rather than treating them as separate unrelated clusters. The report examined a November 2020 Daum/Naver-themed credential-harvesting campaign using domains such as naver.midsecurity.org and 211.104.160.79, where directory exposure revealed additional phishing materials including Russian targets, OHCHR-themed lures, Summitz coin legal documents and Biden-era Korea strategy content. ESRC compared passive DNS, registrant emails and domains cited in Microsoft’s Thallium complaint, including rnaii.com, app-wallet.com and bigwnet.com, to show infrastructure links among Thallium, Kimsuky and Konni activity. The source emphasizes account-theft tradecraft, POP3/IMAP abuse for covert mail collection, and recurring Korean portal impersonation against North Korea-related and other Korean targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 52.177.14.24 | 2019-08-24 | 2025-07-01 |
| DOMAIN | noticeofpleadings.com | 2020-11-22 | 2025-03-12 |
| DOMAIN | bigwnet.com | 2019-09-02 | 2024-05-10 |
| DOMAIN | seoulhobi.biz | 2019-08-24 | 2024-05-10 |
| DOMAIN | helpnaver.com | 2019-08-29 | 2023-05-25 |
| HASH | 6bda04173d5f8491348e33cabc98f1b8 | 2020-11-22 | 2020-11-22 |
| HASH | 0ce1648ff7553189e5b5db2252e27fd5 | 2020-11-22 | 2020-11-22 |
| [email protected] | 2020-11-22 | 2020-11-22 | |
| [email protected] | 2020-11-22 | 2020-11-22 | |
| [email protected] | 2020-11-22 | 2020-11-22 | |
| [email protected] | 2020-11-22 | 2020-11-22 | |
| [email protected] | 2020-11-22 | 2020-11-22 | |
| DOMAIN | login.daum-protect.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | bignaver.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | un.midsecurity.org | 2020-11-22 | 2020-11-22 |
| DOMAIN | cloudsecurityservice.net | 2020-11-22 | 2020-11-22 |
| DOMAIN | midsecurity.org | 2020-11-22 | 2020-11-22 |
| DOMAIN | dhfj.naverdns.co | 2020-11-22 | 2020-11-22 |
| DOMAIN | daum.midsecurity.org | 2020-11-22 | 2020-11-22 |
| DOMAIN | servicenidnaver.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | naver.midsecurity.org | 2020-11-22 | 2020-11-22 |
| DOMAIN | cloudnaver.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | resetprofile.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | resetpolicy.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | netsecurityservice.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | nid.daum-protect.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | mail.resetpolicy.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | mail.servicenidnaver.com | 2020-11-22 | 2020-11-22 |
| DOMAIN | daum.resetprofile.com | 2020-11-22 | 2020-11-22 |
| IPv4 | 211.104.160.84 | 2020-11-22 | 2020-11-22 |
| IPv4 | 211.104.160.88 | 2020-11-22 | 2020-11-22 |
| IPv4 | 211.104.160.79 | 2020-11-22 | 2020-11-22 |
| IPv4 | 27.255.77.110 | 2020-11-22 | 2020-11-22 |
| HASH | 2487a29d1193b5f48d29df02804d8172 | 2019-12-23 | 2020-11-22 |
| HASH | 9e9745415793488ecf0774c7477bf2ae | 2019-12-23 | 2020-11-22 |
| IPv4 | 2.56.151.8 | 2019-12-23 | 2020-11-22 |
| [email protected] | 2019-09-02 | 2020-11-22 | |
| [email protected] | 2019-08-29 | 2020-11-22 | |
| HASH | 29506d03bf3f06df62089bed5af58906 | 2019-08-24 | 2020-11-22 |
| HASH | 9c025c3ff6ec04b7e67c9553ef4e2415 | 2019-08-24 | 2020-11-22 |
| HASH | c1063cfa402e64882d41f88ada87c8d1 | 2019-08-24 | 2020-11-22 |
| HASH | 8384803283c01a529eeaec8128e6a20a | 2019-08-24 | 2020-11-22 |
| HASH | ff9f17fb1dd02186ba461586a1734212 | 2019-08-24 | 2020-11-22 |
| HASH | 6c290d6ddbe317844a4dccdc2259c6c1 | 2019-08-24 | 2020-11-22 |
| HASH | d503c3d182a632ac2c009c30e70951f2 | 2019-08-24 | 2020-11-22 |
| [email protected] | 2019-08-24 | 2020-11-22 | |
| [email protected] | 2019-08-24 | 2020-11-22 | |
| [email protected] | 2019-08-24 | 2020-11-22 | |
| [email protected] | 2019-08-24 | 2020-11-22 | |
| DOMAIN | rnaii.com | 2019-08-24 | 2020-11-22 |
| DOMAIN | app-wallet.com | 2019-08-24 | 2020-11-22 |
| DOMAIN | manage.app-wallet.com | 2019-08-24 | 2020-11-22 |
| DOMAIN | rneail.com | 2019-08-24 | 2020-11-22 |
| IPv4 | 37.72.175.223 | 2019-08-24 | 2020-11-22 |
| IPv4 | 27.255.79.205 | 2019-08-24 | 2020-11-22 |
| IPv4 | 193.148.16.45 | 2019-08-24 | 2020-11-22 |
| IPv4 | 91.235.116.144 | 2019-08-24 | 2020-11-22 |