27개 피싱 사이트 이메일 계정 해킹 사건 중간조사 결과
2016-08-01 • KRSPO • Interim investigation results of 27 phishing site email account hacking incidents •
http://www.spo.go.kr/_custom/spo/_common/board/download.jsp?attach_no=171790
Attachments
South Korean prosecutors reported a spear-phishing operation assessed as likely run by a North Korean hacking organization between January and June 2016. The attackers created 27 phishing sites impersonating Google, Naver, Daum, Microsoft, QQ, government ministries, defense firms, and universities, then targeted about 90 people tied to diplomacy, unification, defense, North Korea research, journalism, and defense industry work. Investigators confirmed 56 account passwords were exposed after victims were lured by security-notice emails into entering credentials on fake password-change pages. The infrastructure and methods overlapped with the Korea Hydro and Nuclear Power case, including the same hosting provider, matching phishing web source code, IP-named credential files collected by FTP, and Shenyang IP space previously linked to Kimsuky-family malware. The case matters because it shows credential theft against Korea-focused government, research, and defense targets using reusable phishing infrastructure and operational patterns.