APT Down - The North Korea Files 공개 자료 상세 분석 보고서

2025-09-22 ENKI file-lists_and_misc.zip

https://www.enki.co.kr/media-center/blog/in-depth-analysis-of-the-apt-down-the-north-korea-files-leak

Thumbnail for APT Down - The North Korea Files 공개 자료 상세 분석 보고서

ENKI’s Korean analysis of the “APT Down - The North Korea Files” leak examines the actor’s VMware workstation and VPS dumps, which contained malware source code, attack tools, stolen data, logs, and phishing infrastructure. The leaked rootkit code matched a rootkit ENKI observed during a 2022 South Korean financial-company incident, and the dump also included a newer 2025 version of the same rootkit/backdoor family. The 2022 syslogk rootkit hides processes, ports, and directories, registers Netfilter hooks, runs the backdoor only after specific magic-packet conditions, and supports encrypted command execution, file transfer, and proxy functions through an operator client. The 2025 version adds callback-delay password checks, configurable callback timing, transfer-rate controls, additional XOR routines, more commands, and expanded Netfilter and hooking behavior. The broader leak also contained an Ivanti 1-day exploit, apparent South Korean government and GPKISecureWebX source code, and phishing evidence aimed at the Public Prosecutor’s Office and Defense Counterintelligence Command, supporting the report’s view of persistent South Korea-focused operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ae49597d8c87d5cf23f485fa0fc138d… 2025-09-22 2025-09-22
HASH 5990b37f9e73a20c2d5605cba72399cc 2025-09-22 2025-09-22
HASH 6f627869fe1f05add75dc039fce970f… 2025-09-22 2025-09-22
HASH 62609005b9ace1387a1065e6a72b7f7… 2025-09-22 2025-09-22
HASH 05b8bbd2fdc2823aceba4857bba8d60… 2025-09-22 2025-09-22
HASH a61080d5ee883489ee8ce40f84569fc3 2025-09-22 2025-09-22
HASH 545644526a2a08dff2dd4e3a812be126 2025-09-22 2025-09-22
HASH 33081eba056e1ad1c8e5618829b84030 2025-09-22 2025-09-22
HASH 12a3bb47535ec0d53953a6fbad43f573 2025-09-22 2025-09-22
HASH b5976580954f47b49a33a5c580610ae… 2025-09-22 2025-09-22
HASH 5fb9604da0d50bce37e53c194ab074b0 2025-09-22 2025-09-22
HASH 0e9cae6dc34ae064b71604c221bca93… 2025-09-22 2025-09-22
URL https://ahrefstop.com/websites/… 2025-09-22 2025-09-22
URL https://ahrefstop.com/websites/… 2025-09-22 2025-09-22
URL https://discussion.fedoraprojec… 2025-09-22 2025-09-22
URL https://ahrefstop.com/websites/… 2025-09-22 2025-09-22
URL https://nid.navermails.com/nidl… 2025-09-22 2025-09-22
URL https://blog.linuxmint.com/?p=4… 2025-09-22 2025-09-22
URL https://ahrefstop.com/websites/… 2025-09-22 2025-09-22
URL https://ahrefstop.com/websites/… 2025-09-22 2025-09-22
DOMAIN zayo.com 2025-09-22 2025-09-22
IPv4 200.63.47.32 2025-09-22 2025-09-22
IPv4 183.99.48.26 2025-09-22 2025-09-22
IPv4 156.59.13.154 2025-09-22 2025-09-22
IPv4 222.99.190.104 2025-09-22 2025-09-22
IPv4 115.90.74.131 2025-09-22 2025-09-22
IPv4 59.12.199.252 2025-09-22 2025-09-22
IPv4 182.162.206.39 2025-09-22 2025-09-22
IPv4 182.162.206.103 2025-09-22 2025-09-22
IPv4 61.98.76.115 2025-09-22 2025-09-22
IPv4 59.18.85.26 2025-09-22 2025-09-22
HASH 603deb15153a715e2b73aef3857d758… 2025-09-22 2025-09-22
HASH efa3c987532cc0bdac533845ad8df5ea 2025-09-22 2025-09-22
HASH d03deb92153a71458973aef3857d75b… 2025-09-22 2025-09-22
EMAIL [email protected] 2025-09-22 2025-09-22
EMAIL [email protected] 2025-09-22 2025-09-22
URL https://mail.yonsei.ac.kr/commo… 2025-09-22 2025-09-22
DOMAIN amiunique.org 2025-09-22 2025-09-22
DOMAIN service.navers.org 2025-09-22 2025-09-22
DOMAIN acfun.cn 2025-09-22 2025-09-22
DOMAIN payload.info 2025-09-22 2025-09-22
DOMAIN nid.navermails.com 2025-09-01 2025-09-22
IPv4 203.234.192.200 2025-08-15 2025-09-22

Related Actors

Related Reports

« Back