APT Down - The North Korea Files 공개 자료 상세 분석 보고서
2025-09-22 • ENKI • file-lists_and_misc.zip •
ENKI’s Korean analysis of the “APT Down - The North Korea Files” leak examines the actor’s VMware workstation and VPS dumps, which contained malware source code, attack tools, stolen data, logs, and phishing infrastructure. The leaked rootkit code matched a rootkit ENKI observed during a 2022 South Korean financial-company incident, and the dump also included a newer 2025 version of the same rootkit/backdoor family. The 2022 syslogk rootkit hides processes, ports, and directories, registers Netfilter hooks, runs the backdoor only after specific magic-packet conditions, and supports encrypted command execution, file transfer, and proxy functions through an operator client. The 2025 version adds callback-delay password checks, configurable callback timing, transfer-rate controls, additional XOR routines, more commands, and expanded Netfilter and hooking behavior. The broader leak also contained an Ivanti 1-day exploit, apparent South Korean government and GPKISecureWebX source code, and phishing evidence aimed at the Public Prosecutor’s Office and Defense Counterintelligence Command, supporting the report’s view of persistent South Korea-focused operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ae49597d8c87d5cf23f485fa0fc138d… | 2025-09-22 | 2025-09-22 |
| HASH | 5990b37f9e73a20c2d5605cba72399cc | 2025-09-22 | 2025-09-22 |
| HASH | 6f627869fe1f05add75dc039fce970f… | 2025-09-22 | 2025-09-22 |
| HASH | 62609005b9ace1387a1065e6a72b7f7… | 2025-09-22 | 2025-09-22 |
| HASH | 05b8bbd2fdc2823aceba4857bba8d60… | 2025-09-22 | 2025-09-22 |
| HASH | a61080d5ee883489ee8ce40f84569fc3 | 2025-09-22 | 2025-09-22 |
| HASH | 545644526a2a08dff2dd4e3a812be126 | 2025-09-22 | 2025-09-22 |
| HASH | 33081eba056e1ad1c8e5618829b84030 | 2025-09-22 | 2025-09-22 |
| HASH | 12a3bb47535ec0d53953a6fbad43f573 | 2025-09-22 | 2025-09-22 |
| HASH | b5976580954f47b49a33a5c580610ae… | 2025-09-22 | 2025-09-22 |
| HASH | 5fb9604da0d50bce37e53c194ab074b0 | 2025-09-22 | 2025-09-22 |
| HASH | 0e9cae6dc34ae064b71604c221bca93… | 2025-09-22 | 2025-09-22 |
| URL | https://ahrefstop.com/websites/… | 2025-09-22 | 2025-09-22 |
| URL | https://ahrefstop.com/websites/… | 2025-09-22 | 2025-09-22 |
| URL | https://discussion.fedoraprojec… | 2025-09-22 | 2025-09-22 |
| URL | https://ahrefstop.com/websites/… | 2025-09-22 | 2025-09-22 |
| URL | https://nid.navermails.com/nidl… | 2025-09-22 | 2025-09-22 |
| URL | https://blog.linuxmint.com/?p=4… | 2025-09-22 | 2025-09-22 |
| URL | https://ahrefstop.com/websites/… | 2025-09-22 | 2025-09-22 |
| URL | https://ahrefstop.com/websites/… | 2025-09-22 | 2025-09-22 |
| DOMAIN | zayo.com | 2025-09-22 | 2025-09-22 |
| IPv4 | 200.63.47.32 | 2025-09-22 | 2025-09-22 |
| IPv4 | 183.99.48.26 | 2025-09-22 | 2025-09-22 |
| IPv4 | 156.59.13.154 | 2025-09-22 | 2025-09-22 |
| IPv4 | 222.99.190.104 | 2025-09-22 | 2025-09-22 |
| IPv4 | 115.90.74.131 | 2025-09-22 | 2025-09-22 |
| IPv4 | 59.12.199.252 | 2025-09-22 | 2025-09-22 |
| IPv4 | 182.162.206.39 | 2025-09-22 | 2025-09-22 |
| IPv4 | 182.162.206.103 | 2025-09-22 | 2025-09-22 |
| IPv4 | 61.98.76.115 | 2025-09-22 | 2025-09-22 |
| IPv4 | 59.18.85.26 | 2025-09-22 | 2025-09-22 |
| HASH | 603deb15153a715e2b73aef3857d758… | 2025-09-22 | 2025-09-22 |
| HASH | efa3c987532cc0bdac533845ad8df5ea | 2025-09-22 | 2025-09-22 |
| HASH | d03deb92153a71458973aef3857d75b… | 2025-09-22 | 2025-09-22 |
| [email protected] | 2025-09-22 | 2025-09-22 | |
| [email protected] | 2025-09-22 | 2025-09-22 | |
| URL | https://mail.yonsei.ac.kr/commo… | 2025-09-22 | 2025-09-22 |
| DOMAIN | amiunique.org | 2025-09-22 | 2025-09-22 |
| DOMAIN | service.navers.org | 2025-09-22 | 2025-09-22 |
| DOMAIN | acfun.cn | 2025-09-22 | 2025-09-22 |
| DOMAIN | payload.info | 2025-09-22 | 2025-09-22 |
| DOMAIN | nid.navermails.com | 2025-09-01 | 2025-09-22 |
| IPv4 | 203.234.192.200 | 2025-08-15 | 2025-09-22 |