AI 딥페이크 기반 군 공무원증 위조 김수키 APT 캠페인

2025-09-14 Genians Kimsuky APT Campaign Using AI Deepfake-Based Forged Military Civil Servant IDs

https://www.genians.co.kr/blog/threat_intelligence/deepfake

Thumbnail for AI 딥페이크 기반 군 공무원증 위조 김수키 APT 캠페인

Genians reports a Kimsuky-attributed spear-phishing campaign that abused ChatGPT-generated deepfake imagery of South Korean military government employee ID cards to make a defense-sector lure appear like an ID issuance review task. The activity is tied to earlier ClickFix phishing against North Korea researchers, human rights activists, and journalists, where portal-security-themed emails directed victims to liveml.cafe24[.]com and triggered PowerShell and batch execution. In the military ID case, a ZIP containing a malicious LNK ran obfuscated cmd logic, contacted jiwooeng.co[.]kr, downloaded a decoy PNG and batch file, and then installed a CAB payload under %Public%. Persistence was registered as a Hancom-like scheduled task loading HncUpdateTray.exe, actually AutoIt3.exe, with config.bin polling C2 using the victim COMPUTERNAME and enabling follow-on reconnaissance, data theft, or remote-control actions. The report also compares related Korean reunification research phishing that reused similar batch obfuscation markers such as Start_juice and Eextract_juice but deployed a Python-based payload chain.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 009bb71299a4f74fe00cf7b8cd26fdfc 2025-09-14 2025-09-14
HASH 143d845b6bae947998c3c8d3eb62c3af 2025-09-14 2025-09-14
HASH 1b2e63ca745043b9427153dc2d4d4635 2025-09-14 2025-09-14
HASH 33c97fc4eacd73addbae9e6cde54a77d 2025-09-14 2025-09-14
HASH fcb97f87905a33af565b0a4f4e884d61 2025-09-14 2025-09-14
HASH bd0e6e02814cf6dcfda9c3c232987756 2025-09-14 2025-09-14
HASH 09dabe5ab566e50ab4526504345af297 2025-09-14 2025-09-14
HASH 8684e5935d9ce47df2da77af7b9d93fb 2025-09-14 2025-09-14
HASH 227973069e288943021e4c8010a94b3c 2025-09-14 2025-09-14
HASH 472610c4c684cea1b4af36f794eedcb0 2025-09-14 2025-09-14
HASH eacf377577cfebe882d215be9515fd11 2025-09-14 2025-09-14
EMAIL [email protected] 2025-09-14 2025-09-14
URL http://www.jiwooeng.co.kr/zb41p… 2025-09-14 2025-09-14
DOMAIN jiwooeng.co.kr 2025-09-14 2025-09-14
DOMAIN seytroux.fr 2025-09-14 2025-09-14
DOMAIN zabel-partners.com 2025-09-14 2025-09-14
DOMAIN snuopel.cafe24.com 2025-09-14 2025-09-14
DOMAIN astaibs.co.kr 2025-09-14 2025-09-14
DOMAIN contamine-sarzin.fr 2025-09-14 2025-09-14
DOMAIN hyounwoolab.com 2025-09-14 2025-09-14
DOMAIN versonnex74.fr 2025-09-14 2025-09-14
DOMAIN healthindustry.sookmyung.ac.kr 2025-09-14 2025-09-14
IPv4 112.175.184.4 2025-09-14 2025-09-14
IPv4 183.111.174.34 2025-09-14 2025-09-14
IPv4 183.111.174.97 2025-09-14 2025-09-14
IPv4 59.25.184.83 2025-09-14 2025-09-14
IPv4 184.168.108.207 2025-09-14 2025-09-14
IPv4 51.158.21.1 2025-09-14 2025-09-14
IPv4 111.92.189.12 2025-09-14 2025-09-14
IPv4 183.111.182.195 2025-09-14 2025-09-14
IPv4 121.254.129.86 2025-09-14 2025-09-14
HASH 90026c2dbdb294b13fd03da2be011dd1 2025-03-20 2025-09-14
IPv4 58.229.208.146 2021-06-01 2025-09-14
IPv4 183.111.161.96 2013-04-24 2025-09-14

Related Actors

Related Reports

« Back