AI 딥페이크 기반 군 공무원증 위조 김수키 APT 캠페인
2025-09-14 • Genians • Kimsuky APT Campaign Using AI Deepfake-Based Forged Military Civil Servant IDs •
Genians reports a Kimsuky-attributed spear-phishing campaign that abused ChatGPT-generated deepfake imagery of South Korean military government employee ID cards to make a defense-sector lure appear like an ID issuance review task. The activity is tied to earlier ClickFix phishing against North Korea researchers, human rights activists, and journalists, where portal-security-themed emails directed victims to liveml.cafe24[.]com and triggered PowerShell and batch execution. In the military ID case, a ZIP containing a malicious LNK ran obfuscated cmd logic, contacted jiwooeng.co[.]kr, downloaded a decoy PNG and batch file, and then installed a CAB payload under %Public%. Persistence was registered as a Hancom-like scheduled task loading HncUpdateTray.exe, actually AutoIt3.exe, with config.bin polling C2 using the victim COMPUTERNAME and enabling follow-on reconnaissance, data theft, or remote-control actions. The report also compares related Korean reunification research phishing that reused similar batch obfuscation markers such as Start_juice and Eextract_juice but deployed a Python-based payload chain.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 009bb71299a4f74fe00cf7b8cd26fdfc | 2025-09-14 | 2025-09-14 |
| HASH | 143d845b6bae947998c3c8d3eb62c3af | 2025-09-14 | 2025-09-14 |
| HASH | 1b2e63ca745043b9427153dc2d4d4635 | 2025-09-14 | 2025-09-14 |
| HASH | 33c97fc4eacd73addbae9e6cde54a77d | 2025-09-14 | 2025-09-14 |
| HASH | fcb97f87905a33af565b0a4f4e884d61 | 2025-09-14 | 2025-09-14 |
| HASH | bd0e6e02814cf6dcfda9c3c232987756 | 2025-09-14 | 2025-09-14 |
| HASH | 09dabe5ab566e50ab4526504345af297 | 2025-09-14 | 2025-09-14 |
| HASH | 8684e5935d9ce47df2da77af7b9d93fb | 2025-09-14 | 2025-09-14 |
| HASH | 227973069e288943021e4c8010a94b3c | 2025-09-14 | 2025-09-14 |
| HASH | 472610c4c684cea1b4af36f794eedcb0 | 2025-09-14 | 2025-09-14 |
| HASH | eacf377577cfebe882d215be9515fd11 | 2025-09-14 | 2025-09-14 |
| [email protected] | 2025-09-14 | 2025-09-14 | |
| URL | http://www.jiwooeng.co.kr/zb41p… | 2025-09-14 | 2025-09-14 |
| DOMAIN | jiwooeng.co.kr | 2025-09-14 | 2025-09-14 |
| DOMAIN | seytroux.fr | 2025-09-14 | 2025-09-14 |
| DOMAIN | zabel-partners.com | 2025-09-14 | 2025-09-14 |
| DOMAIN | snuopel.cafe24.com | 2025-09-14 | 2025-09-14 |
| DOMAIN | astaibs.co.kr | 2025-09-14 | 2025-09-14 |
| DOMAIN | contamine-sarzin.fr | 2025-09-14 | 2025-09-14 |
| DOMAIN | hyounwoolab.com | 2025-09-14 | 2025-09-14 |
| DOMAIN | versonnex74.fr | 2025-09-14 | 2025-09-14 |
| DOMAIN | healthindustry.sookmyung.ac.kr | 2025-09-14 | 2025-09-14 |
| IPv4 | 112.175.184.4 | 2025-09-14 | 2025-09-14 |
| IPv4 | 183.111.174.34 | 2025-09-14 | 2025-09-14 |
| IPv4 | 183.111.174.97 | 2025-09-14 | 2025-09-14 |
| IPv4 | 59.25.184.83 | 2025-09-14 | 2025-09-14 |
| IPv4 | 184.168.108.207 | 2025-09-14 | 2025-09-14 |
| IPv4 | 51.158.21.1 | 2025-09-14 | 2025-09-14 |
| IPv4 | 111.92.189.12 | 2025-09-14 | 2025-09-14 |
| IPv4 | 183.111.182.195 | 2025-09-14 | 2025-09-14 |
| IPv4 | 121.254.129.86 | 2025-09-14 | 2025-09-14 |
| HASH | 90026c2dbdb294b13fd03da2be011dd1 | 2025-03-20 | 2025-09-14 |
| IPv4 | 58.229.208.146 | 2021-06-01 | 2025-09-14 |
| IPv4 | 183.111.161.96 | 2013-04-24 | 2025-09-14 |