2021년 상반기 Kimsuky 공격 동향

2021-09-01 Igloo Kimsuky attack trends in the first half of 2021

https://www.igloo.co.kr/security-information/2021%eb%85%84-%ec%83%81%eb%b0%98%ea%b8%b0-kimsuky-%ea%b3%b5%ea%b2%a9-%eb%8f%99%ed%96%a5/

Thumbnail for 2021년 상반기 Kimsuky 공격 동향

IGLOO’s first-half 2021 Kimsuky trend report documents repeated Korea-focused phishing and malware operations that used malicious documents, VBA or PowerShell logic, HWP-delivered DLL/VBS stages, and attacker-controlled web infrastructure to collect host data and upload it to C2. The cases include lures such as conference or survey materials, policy-committee lists, payment-request forms, and Korean-language organization themes, with delivery through Google Blog, OneDrive, and compromised or disposable domains. The excerpt lists many hashes and defanged URLs, but the operational pattern is more important than any single indicator: Kimsuky repeatedly collected PC/user information, created shortcuts or configuration files for execution, downloaded follow-on scripts or binaries, and used PHP endpoints for staging and exfiltration. This summary should be treated as a trend-level archive entry rather than a single-incident attribution beyond the source’s Kimsuky framing.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 04a0505cc45d2dac4be9387768efcb7c 2021-07-26 2023-10-30
DOMAIN yanggucam.designsoup.co.kr 2021-07-26 2023-10-30
DOMAIN samsoding.homm7.gethompy.com 2021-07-26 2023-10-30
DOMAIN heritage2020.cafe24.com 2021-07-26 2023-10-30
DOMAIN beilksa.scienceontheweb.net 2021-04-02 2023-10-30
DOMAIN miracle.designsoup.co.kr 2021-07-26 2023-06-14
URL http://eucie09111.myartsonline.… 2021-07-26 2021-11-10
DOMAIN eucie09111.myartsonline.com 2021-07-26 2021-11-10
URL http://quarez.atwebpages.com/ds… 2021-07-26 2021-11-01
URL http://manct.atwebpages.com/ck/… 2021-07-26 2021-11-01
DOMAIN manct.atwebpages.com 2021-07-26 2021-11-01
DOMAIN quarez.atwebpages.com 2021-03-10 2021-11-01
URL http://www.inonix.co.kr/kor/pag… 2021-09-01 2021-09-01
URL http://yanggucam.designsoup.co.… 2021-09-01 2021-09-01
URL http://miracle.designsoup.co.kr… 2021-09-01 2021-09-01
URL http://samsoding.homm7.gethompy… 2021-09-01 2021-09-01
URL https://worldinfocontact.club/1… 2021-09-01 2021-09-01
URL http://beilksa.scienceontheweb.… 2021-09-01 2021-09-01
URL http://cwda.co.kr/theme/basic/s… 2021-09-01 2021-09-01
URL http://cwda.co.kr/theme/basic/s… 2021-09-01 2021-09-01
URL http://www.mechapia.com/_admin/… 2021-09-01 2021-09-01
IPv4 200.200.200.200 2021-09-01 2021-09-01
HASH bce51419fae8acbeff3149ca53f8baad 2021-07-26 2021-09-01
HASH 4886f89546c422f5e04c2da33090a201 2021-07-26 2021-09-01
HASH 9ee9dacd6703c74e959a70a18ebb3875 2021-07-26 2021-09-01
HASH ec3f771c71a24c165697e26e136daa4a 2021-07-26 2021-09-01
HASH d8e817abd5ad765bf7acec5d672cbb8d 2021-07-26 2021-09-01
HASH 1269e2b00fd323a7748215124cb058cd 2021-07-26 2021-09-01
HASH 0d36f4f5a1f7bc7d89fbda02be7c2336 2021-07-26 2021-09-01
HASH d725efd437d26e01e3b64e722929c01e 2021-07-26 2021-09-01
HASH c9f23b6ee1ba97c753892e6c103521d6 2021-07-26 2021-09-01
HASH d3a317dd167cfa77c976fa9c86c24982 2021-07-26 2021-09-01
HASH 5973ba270e9b5ea57c138245ffc39552 2021-07-26 2021-09-01
HASH dfbe17d9dfa3f3bb715e1d8348bd1f50 2021-07-26 2021-09-01
HASH 5b2355014f72dc2714dc5a5f04fe9519 2021-07-26 2021-09-01
HASH af3288ed7853865d562ccd1f48fa4a16 2021-07-26 2021-09-01
HASH 86c462b8ceffbc10018df2c32e024b29 2021-07-26 2021-09-01
HASH dc5fa08c7e2bb959042f5572c91ada5e 2021-07-26 2021-09-01
HASH 208a3b4565d3041d09448a23a80edf1c 2021-07-26 2021-09-01
HASH 49a04c85555b35f998b1787b325526e6 2021-07-26 2021-09-01
HASH 6a614ca002c5b3a4d7023faffc0546e1 2021-07-26 2021-09-01
HASH 8ca84c206fe8436dcc92bf6c1f7cf168 2021-07-26 2021-09-01
HASH 0a68d6a3d0aa9c5a3a4485d314ea8372 2021-07-26 2021-09-01
HASH 9d3b4e82d2c839ffc2887946fb204615 2021-07-26 2021-09-01
HASH 36ad6b5775ac550a36f56467051d2c03 2021-07-26 2021-09-01
HASH d7b717134358bbeefc5796b5912369f0 2021-07-26 2021-09-01
HASH c6437d685f4a489c867b4d2b68f07f1a 2021-07-26 2021-09-01
URL http://connectter.atwebpages.co… 2021-07-26 2021-09-01
URL http://pootball.medianewsonline… 2021-07-26 2021-09-01
URL http://quarez.atwebpages.com/ny… 2021-07-26 2021-09-01
URL http://waels.onlinewebshop.net/… 2021-07-26 2021-09-01
URL https://worldinfocontact.club/1… 2021-07-26 2021-09-01
URL http://heritage2020.cafe24.com/… 2021-07-26 2021-09-01
URL http://majar.medianewsonline.co… 2021-07-26 2021-09-01
URL http://wbg0909.scienceontheweb.… 2021-07-26 2021-09-01
URL http://quarez.atwebpages.com/ny… 2021-07-26 2021-09-01
URL http://fabre.myartsonline.com/y… 2021-07-26 2021-09-01
URL http://www.inonix.co.kr/kor/pag… 2021-07-26 2021-09-01
URL http://hanlight.mygamesonline.o… 2021-07-26 2021-09-01
DOMAIN hanlight.mygamesonline.org 2021-07-26 2021-09-01
DOMAIN majar.medianewsonline.com 2021-07-26 2021-09-01
DOMAIN worldinfocontact.club 2021-07-26 2021-09-01
DOMAIN pootball.medianewsonline.com 2021-07-26 2021-09-01
DOMAIN cwda.co.kr 2021-07-26 2021-09-01
DOMAIN connectter.atwebpages.com 2021-07-26 2021-09-01
DOMAIN waels.onlinewebshop.net 2021-07-26 2021-09-01
DOMAIN fabre.myartsonline.com 2021-07-26 2021-09-01
HASH 0821884168a644f3c27176a52763acc9 2021-07-19 2021-09-01
HASH 95c92bcfc39ceafc1735f190a575c60c 2021-07-19 2021-09-01
DOMAIN wbg0909.scienceontheweb.net 2021-07-19 2021-09-01
URL http://ftcpark59.getenjoyment.n… 2021-06-09 2021-09-01
URL http://alyssalove.getenjoyment.… 2021-06-09 2021-09-01
DOMAIN alyssalove.getenjoyment.net 2021-06-09 2021-09-01
URL http://rukagu.mypressonline.com… 2021-05-24 2021-09-01
DOMAIN rukagu.mypressonline.com 2021-05-24 2021-09-01
HASH 199674e87f437bdbd68884b155346d25 2021-05-06 2021-09-01
URL http://beilksa.scienceontheweb.… 2021-04-02 2021-09-01
DOMAIN ftcpark59.getenjoyment.net 2021-03-26 2021-09-01

Related Actors

Related Reports

« Back