CREDENTIALS GATHERING CAMPAIGN
2019-09-02 • CERT-SSI •
https://www.cert.ssi.gouv.fr/uploads/CERTFR-2019-CTI-002-EN.pdf
Attachments
CERTFR-2019-CTI-002-EN.pdf (1 MB)
ANSSI identified a credentials-gathering campaign active since at least 2017 that used spearphishing emails, phishing websites, and large clusters of lookalike domains and subdomains. The infrastructure appeared to target diplomatic bodies, ministries of foreign affairs, UN-related entities, think tanks, Stanford University, South Korea's foreign ministry, and regional email providers. Several domains spoofed cloud, mail, and document services, with many subdomains resolving in the 157.7.184.0/24 range hosted in Japan and grouped by shared registration emails or naming patterns. ANSSI did not attribute the campaign, but noted technical links between some infrastructure and open-source reporting on Kimsuky and Group123, including doc-view.work and mailacounts.com/NavRAT references. The reporting matters because it gives defenders concrete phishing infrastructure and target patterns for monitoring credential-theft activity against strategic organizations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7ca1a603a7440f1031c666afbe44afc8 | 2019-09-02 | 2024-12-02 |
| DOMAIN | bigwnet.com | 2019-09-02 | 2024-05-10 |
| DOMAIN | login-main.bigwnet.com | 2019-09-02 | 2024-05-10 |
| [email protected] | 2019-09-02 | 2020-11-22 | |
| HASH | e12d0655cc09cddb4fb836c641f7317… | 2019-09-02 | 2019-09-02 |
| HASH | 9c6f6db86b5ccdda884369c9c52dd85… | 2019-09-02 | 2019-09-02 |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| [email protected] | 2019-09-02 | 2019-09-02 | |
| URL | https://heehorse.com/heehorse_c… | 2019-09-02 | 2019-09-02 |
| URL | http://www.china-un.org/eng/dbt… | 2019-09-02 | 2019-09-02 |
| DOMAIN | asaninst.info | 2019-09-02 | 2019-09-02 |
| DOMAIN | gstaticstorage.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | drog-service.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | mailseco.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | sec-live.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | hotrnall.co | 2019-09-02 | 2019-09-02 |
| DOMAIN | dauurn.net | 2019-09-02 | 2019-09-02 |
| DOMAIN | login-sec.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | login-yahoo.info | 2019-09-02 | 2019-09-02 |
| DOMAIN | poczta.hotrnall.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | ahooc.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | dounn.net | 2019-09-02 | 2019-09-02 |
| DOMAIN | viewetherwallet.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | logins-yahoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | login-use.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | log-yahoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | hotrnall.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | heehorse.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | set-login.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | lh-yahoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | mail.aei.org | 2019-09-02 | 2019-09-02 |
| DOMAIN | imap-login.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | lh-login.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | user-accounts.net | 2019-09-02 | 2019-09-02 |
| DOMAIN | lh-logs.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | mai1.info | 2019-09-02 | 2019-09-02 |
| DOMAIN | login-history.vip-sina.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | politico.eu.mai1.info | 2019-09-02 | 2019-09-02 |
| DOMAIN | dovvn-mail.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | mail.unperu.yalnoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | inbox-yahoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | mail-down.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | yrnall.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | china-un.org | 2019-09-02 | 2019-09-02 |
| DOMAIN | members.dauurn.net | 2019-09-02 | 2019-09-02 |
| DOMAIN | srnbc-card.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | naver.mai1.info | 2019-09-02 | 2019-09-02 |
| DOMAIN | yalnoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | matmiho.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | phlogin.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | wallet-vahoo.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | il.daumcdn.net.mailacounts.com | 2019-09-02 | 2019-09-02 |
| DOMAIN | eposcard.co | 2019-09-02 | 2019-09-02 |
| DOMAIN | mailacounts.com | 2018-05-31 | 2019-09-02 |