Dissecting Kimsuky's Attacks on South Korea: In-Depth Analysis of GitHub-Based Malicious Infrastructure
2025-06-19 • ENKI •
ENKI links a GitHub-based spearphishing infrastructure cluster to the DPRK-nexus actor Kimsuky through XenoRAT C2 analysis and attacker repository evidence. The campaign targeted South Korean individuals with decoys such as law-firm debt notices, powers of attorney, traffic accident documents, and Financial Supervisory Service-themed account notices. Malware staged RTF-named compressed payloads from Dropbox and GitHub, then decompressed and executed XenoRAT-like .NET payloads in a fileless manner. Hardcoded GitHub Personal Access Tokens with repo scope let the operators access private repositories, download payloads, and upload victim telemetry including OS details, process lists, boot time, page titles, and possible keylogging data. Infrastructure and artifacts included accounts Dasi274 and luckmask, commit email [email protected], C2 servers 158.247.230.196:443, 216.244.74.115:80, and 165.154.78.9:443, plus attacker test IPs such as 158.247.253.215 and 139.99.36.158.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
| IPv4 | 158.247.230.196 | 2025-06-19 | 2026-04-17 |
| IPv4 | 158.247.202.109 | 2025-06-19 | 2026-04-17 |
| IPv4 | 141.164.41.17 | 2025-06-19 | 2025-08-18 |
| HASH | b99c1d9bf70be5172a8b36b098c67ee5 | 2025-06-19 | 2025-06-19 |
| HASH | 8c84d7f559cf0947fbf1981a0acb8a35 | 2025-06-19 | 2025-06-19 |
| HASH | 57015267d06b0d80721015ccd29a04cd | 2025-06-19 | 2025-06-19 |
| HASH | f692c1dd797f68c34744a377482c4ed4 | 2025-06-19 | 2025-06-19 |
| HASH | 74b1d5f857a4245aef8189ac4f409a99 | 2025-06-19 | 2025-06-19 |
| HASH | 976ad041832082f2d304df12b61457cb | 2025-06-19 | 2025-06-19 |
| HASH | 5076c579e378f976a57e862e5b6a7859 | 2025-06-19 | 2025-06-19 |
| HASH | af999c3c615b56691d75e8c877e185fb | 2025-06-19 | 2025-06-19 |
| HASH | 522a122f3cd4c488a51d81c846bfabbb | 2025-06-19 | 2025-06-19 |
| HASH | 6cbc007799b56682ac196e44d79e496d | 2025-06-19 | 2025-06-19 |
| HASH | 7df07ecb0b516df085a5ee95ed8e6560 | 2025-06-19 | 2025-06-19 |
| HASH | b13ffe7b8e351291250f1a3a855134aa | 2025-06-19 | 2025-06-19 |
| HASH | c2f88038d431bb190454fae02225e639 | 2025-06-19 | 2025-06-19 |
| HASH | f51a2ccb4b9b2bf163c81b525bfac08e | 2025-06-19 | 2025-06-19 |
| HASH | b36159563452d9a837a5e566ad2a1e44 | 2025-06-19 | 2025-06-19 |
| HASH | a9d80e7fe3f217ea4d33f8a4a0f3f73c | 2025-06-19 | 2025-06-19 |
| HASH | acd2d728ee4d1110521524c1eac6204e | 2025-06-19 | 2025-06-19 |
| HASH | 8c561a53085651d7f47b24129c2cd2d0 | 2025-06-19 | 2025-06-19 |
| HASH | d0a8cd7584547bdb2959f0d1008e6871 | 2025-06-19 | 2025-06-19 |
| HASH | b77e4e9f5897f00dcbd08b2ee9bde7e8 | 2025-06-19 | 2025-06-19 |
| HASH | a87659641e00d724de5662b14fe142e8 | 2025-06-19 | 2025-06-19 |
| HASH | 5e9a80d3d4f71ecd8bf8e579a5e2449c | 2025-06-19 | 2025-06-19 |
| HASH | 45ed6abfc12be606bdbcfe76bd17b2af | 2025-06-19 | 2025-06-19 |
| HASH | 5be0527f5c84208371761cee852f0d7c | 2025-06-19 | 2025-06-19 |
| HASH | baf164d2a5066cab5772dc6ae4807f43 | 2025-06-19 | 2025-06-19 |
| HASH | 0cb6e67f23ccebc3727f755be5140497 | 2025-06-19 | 2025-06-19 |
| HASH | a56edfef94008c77abfb4e151df934d9 | 2025-06-19 | 2025-06-19 |
| HASH | 10ce9409d8d1e72ea6439bec7cd7e4cd | 2025-06-19 | 2025-06-19 |
| HASH | 30d5f17d5e3f85be18220a7cab0b9fff | 2025-06-19 | 2025-06-19 |
| HASH | 157d1b1798f0f370a95125253e039c18 | 2025-06-19 | 2025-06-19 |
| HASH | 1dee4c60fffcc80eb4bbd523eedab2f4 | 2025-06-19 | 2025-06-19 |
| HASH | 1808bd4919c5943096a4a19784d6b8de | 2025-06-19 | 2025-06-19 |
| [email protected] | 2025-06-19 | 2025-06-19 | |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-06-19 | 2025-06-19 |
| IPv4 | 139.99.36.158 | 2025-06-19 | 2025-06-19 |
| IPv4 | 118.194.249.201 | 2025-06-19 | 2025-06-19 |
| IPv4 | 158.247.253.215 | 2025-06-19 | 2025-06-19 |
| IPv4 | 216.244.74.115 | 2025-06-19 | 2025-06-19 |
| IPv4 | 45.61.161.103 | 2025-06-19 | 2025-06-19 |
| IPv4 | 165.154.78.9 | 2025-06-19 | 2025-06-19 |
| HASH | 85f5075610661c9706571a33548d7585 | 2025-03-17 | 2025-06-19 |
| IPv4 | 101.36.114.190 | 2025-03-17 | 2025-06-19 |
| URL | https://dl.dropboxusercontent.c… | 2025-02-13 | 2025-06-19 |
| IPv4 | 80.71.157.55 | 2024-08-21 | 2025-06-19 |