Identifying North Korean Kimsuky (APT43) Infrastructure

2025-06-17 LCSC-IE

https://medium.com/@LCSC-IE/identifying-north-korean-kimsuky-apt43-infrastructure-b6817a58a65b

Thumbnail for Identifying North Korean Kimsuky (APT43) Infrastructure

The investigation pivots from 158.247.215[.]121 to infrastructure assessed with high confidence as related to Kimsuky/APT43. The observed hosts used Vultr infrastructure, exposed RDP, WinRM, HTTP services, and a repeated RDP certificate common name, CN=Computer-FA06W7, to identify related systems. Passive DNS and URLscan pivots surfaced South Korea-themed domains impersonating government, tax, police, document, Naver Works, and crypto-login services, including domains tied to IPs such as 141.164.51[.]224, 158.247.204[.]137, 158.247.242[.]206, 158.247.247[.]157, 141.164.55[.]2, and 27.102.138[.]10. The analysis also highlights recurring resource hashes and a suspicious mail.ru[.]php file that helped connect additional captures and infrastructure. The value of the report is in its repeatable pivot method for tracking suspected Kimsuky infrastructure through certificate reuse, hosting patterns, passive DNS, and URLscan artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 158.247.192.226 2025-06-17 2026-04-17
IPv4 158.247.242.206 2025-06-17 2026-04-17
IPv4 158.247.215.121 2025-06-17 2026-04-17
IPv4 158.247.204.137 2025-06-17 2026-04-17
HASH 26ba5b01f614a215b948a5700338575… 2025-06-17 2025-06-17
HASH 9947d3f5c4ea436c15a94373cb36e46… 2025-06-17 2025-06-17
HASH 04d14da053c42397c48a54fe61850dd… 2025-06-17 2025-06-17
DOMAIN login.online-mexc.kro.kr 2025-06-17 2025-06-17
DOMAIN coupick.co.kr 2025-06-17 2025-06-17
DOMAIN nts.departmentedoc.r-e.kr 2025-06-17 2025-06-17
DOMAIN nid.policegoalsvc.p-e.kr 2025-06-17 2025-06-17
DOMAIN hometx.taxdepartmentsvc.kro.kr 2025-06-17 2025-06-17
DOMAIN brownsix.com 2025-06-17 2025-06-17
IPv4 141.164.51.224 2025-06-17 2025-06-17
IPv4 141.164.55.2 2025-06-17 2025-06-17
IPv4 158.247.247.157 2025-06-02 2025-06-17
HASH 9b43f670273b6a12b2b6894a9e29157… 2022-11-23 2025-06-17

Related Actors

Related Reports

« Back