Dissecting Kimsuky's Attacks on South Korea: In-Depth Analysis of GitHub-Based Malicious Infrastructure

2025-06-19 ENKI

https://www.enki.co.kr/en/media-center/tech-blog/dissecting-kimsuky-s-attacks-on-south-korea-in-depth-analysis-of-github-based-malicious-infrastructure

Thumbnail for Dissecting Kimsuky's Attacks on South Korea: In-Depth Analysis of GitHub-Based Malicious Infrastructure

ENKI links a GitHub-based spearphishing infrastructure cluster to the DPRK-nexus actor Kimsuky through XenoRAT C2 analysis and attacker repository evidence. The campaign targeted South Korean individuals with decoys such as law-firm debt notices, powers of attorney, traffic accident documents, and Financial Supervisory Service-themed account notices. Malware staged RTF-named compressed payloads from Dropbox and GitHub, then decompressed and executed XenoRAT-like .NET payloads in a fileless manner. Hardcoded GitHub Personal Access Tokens with repo scope let the operators access private repositories, download payloads, and upload victim telemetry including OS details, process lists, boot time, page titles, and possible keylogging data. Infrastructure and artifacts included accounts Dasi274 and luckmask, commit email [email protected], C2 servers 158.247.230.196:443, 216.244.74.115:80, and 165.154.78.9:443, plus attacker test IPs such as 158.247.253.215 and 139.99.36.158.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN p-e.kr 2021-12-21 2026-06-01
IPv4 158.247.230.196 2025-06-19 2026-04-17
IPv4 158.247.202.109 2025-06-19 2026-04-17
IPv4 141.164.41.17 2025-06-19 2025-08-18
HASH b99c1d9bf70be5172a8b36b098c67ee5 2025-06-19 2025-06-19
HASH 8c84d7f559cf0947fbf1981a0acb8a35 2025-06-19 2025-06-19
HASH 57015267d06b0d80721015ccd29a04cd 2025-06-19 2025-06-19
HASH f692c1dd797f68c34744a377482c4ed4 2025-06-19 2025-06-19
HASH 74b1d5f857a4245aef8189ac4f409a99 2025-06-19 2025-06-19
HASH 976ad041832082f2d304df12b61457cb 2025-06-19 2025-06-19
HASH 5076c579e378f976a57e862e5b6a7859 2025-06-19 2025-06-19
HASH af999c3c615b56691d75e8c877e185fb 2025-06-19 2025-06-19
HASH 522a122f3cd4c488a51d81c846bfabbb 2025-06-19 2025-06-19
HASH 6cbc007799b56682ac196e44d79e496d 2025-06-19 2025-06-19
HASH 7df07ecb0b516df085a5ee95ed8e6560 2025-06-19 2025-06-19
HASH b13ffe7b8e351291250f1a3a855134aa 2025-06-19 2025-06-19
HASH c2f88038d431bb190454fae02225e639 2025-06-19 2025-06-19
HASH f51a2ccb4b9b2bf163c81b525bfac08e 2025-06-19 2025-06-19
HASH b36159563452d9a837a5e566ad2a1e44 2025-06-19 2025-06-19
HASH a9d80e7fe3f217ea4d33f8a4a0f3f73c 2025-06-19 2025-06-19
HASH acd2d728ee4d1110521524c1eac6204e 2025-06-19 2025-06-19
HASH 8c561a53085651d7f47b24129c2cd2d0 2025-06-19 2025-06-19
HASH d0a8cd7584547bdb2959f0d1008e6871 2025-06-19 2025-06-19
HASH b77e4e9f5897f00dcbd08b2ee9bde7e8 2025-06-19 2025-06-19
HASH a87659641e00d724de5662b14fe142e8 2025-06-19 2025-06-19
HASH 5e9a80d3d4f71ecd8bf8e579a5e2449c 2025-06-19 2025-06-19
HASH 45ed6abfc12be606bdbcfe76bd17b2af 2025-06-19 2025-06-19
HASH 5be0527f5c84208371761cee852f0d7c 2025-06-19 2025-06-19
HASH baf164d2a5066cab5772dc6ae4807f43 2025-06-19 2025-06-19
HASH 0cb6e67f23ccebc3727f755be5140497 2025-06-19 2025-06-19
HASH a56edfef94008c77abfb4e151df934d9 2025-06-19 2025-06-19
HASH 10ce9409d8d1e72ea6439bec7cd7e4cd 2025-06-19 2025-06-19
HASH 30d5f17d5e3f85be18220a7cab0b9fff 2025-06-19 2025-06-19
HASH 157d1b1798f0f370a95125253e039c18 2025-06-19 2025-06-19
HASH 1dee4c60fffcc80eb4bbd523eedab2f4 2025-06-19 2025-06-19
HASH 1808bd4919c5943096a4a19784d6b8de 2025-06-19 2025-06-19
EMAIL [email protected] 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-06-19 2025-06-19
IPv4 139.99.36.158 2025-06-19 2025-06-19
IPv4 118.194.249.201 2025-06-19 2025-06-19
IPv4 158.247.253.215 2025-06-19 2025-06-19
IPv4 216.244.74.115 2025-06-19 2025-06-19
IPv4 45.61.161.103 2025-06-19 2025-06-19
IPv4 165.154.78.9 2025-06-19 2025-06-19
HASH 85f5075610661c9706571a33548d7585 2025-03-17 2025-06-19
IPv4 101.36.114.190 2025-03-17 2025-06-19
URL https://dl.dropboxusercontent.c… 2025-02-13 2025-06-19
IPv4 80.71.157.55 2024-08-21 2025-06-19

Related Actors

Related Reports

« Back