Identifying North Korean Kimsuky (APT43) Infrastructure
2025-06-17 • LCSC-IE •
https://medium.com/@LCSC-IE/identifying-north-korean-kimsuky-apt43-infrastructure-b6817a58a65b
The investigation pivots from 158.247.215[.]121 to infrastructure assessed with high confidence as related to Kimsuky/APT43. The observed hosts used Vultr infrastructure, exposed RDP, WinRM, HTTP services, and a repeated RDP certificate common name, CN=Computer-FA06W7, to identify related systems. Passive DNS and URLscan pivots surfaced South Korea-themed domains impersonating government, tax, police, document, Naver Works, and crypto-login services, including domains tied to IPs such as 141.164.51[.]224, 158.247.204[.]137, 158.247.242[.]206, 158.247.247[.]157, 141.164.55[.]2, and 27.102.138[.]10. The analysis also highlights recurring resource hashes and a suspicious mail.ru[.]php file that helped connect additional captures and infrastructure. The value of the report is in its repeatable pivot method for tracking suspected Kimsuky infrastructure through certificate reuse, hosting patterns, passive DNS, and URLscan artifacts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 158.247.192.226 | 2025-06-17 | 2026-04-17 |
| IPv4 | 158.247.242.206 | 2025-06-17 | 2026-04-17 |
| IPv4 | 158.247.215.121 | 2025-06-17 | 2026-04-17 |
| IPv4 | 158.247.204.137 | 2025-06-17 | 2026-04-17 |
| HASH | 26ba5b01f614a215b948a5700338575… | 2025-06-17 | 2025-06-17 |
| HASH | 9947d3f5c4ea436c15a94373cb36e46… | 2025-06-17 | 2025-06-17 |
| HASH | 04d14da053c42397c48a54fe61850dd… | 2025-06-17 | 2025-06-17 |
| DOMAIN | login.online-mexc.kro.kr | 2025-06-17 | 2025-06-17 |
| DOMAIN | coupick.co.kr | 2025-06-17 | 2025-06-17 |
| DOMAIN | nts.departmentedoc.r-e.kr | 2025-06-17 | 2025-06-17 |
| DOMAIN | nid.policegoalsvc.p-e.kr | 2025-06-17 | 2025-06-17 |
| DOMAIN | hometx.taxdepartmentsvc.kro.kr | 2025-06-17 | 2025-06-17 |
| DOMAIN | brownsix.com | 2025-06-17 | 2025-06-17 |
| IPv4 | 141.164.51.224 | 2025-06-17 | 2025-06-17 |
| IPv4 | 141.164.55.2 | 2025-06-17 | 2025-06-17 |
| IPv4 | 158.247.247.157 | 2025-06-02 | 2025-06-17 |
| HASH | 9b43f670273b6a12b2b6894a9e29157… | 2022-11-23 | 2025-06-17 |