In-Depth Analysis of the APT Down - The North Korea Files leak

2025-09-22 ENKI

https://www.enki.co.kr/en/media-center/blog/in-depth-analysis-of-the-apt-down-the-north-korea-files-leak

Thumbnail for In-Depth Analysis of the APT Down - The North Korea Files leak

The leaked “APT Down - The North Korea Files” material exposed a Deepin workstation dump and VPS data containing malware source code, attack tools, exfiltrated material, and phishing infrastructure tied by the authors to activity against South Korea. ENKI found rootkit source code matching a rootkit from its 2022 investigation at a South Korean financial institution, including identical logic and encryption material, plus an updated 2025 version. The tooling includes a syslogk Linux rootkit and companion backdoor that hide processes, ports, and directories, use Netfilter hooks and magic-packet triggering, support command execution, file transfer, and proxying, and mask traffic as common protocols. The leak also contained an Ivanti 1-day exploit, apparent Ministry of Foreign Affairs and GPKISecureWebX source code, and spear-phishing evidence targeting entities such as the Public Prosecutor’s Office and Defense Counterintelligence Command, indicating sustained operations against South Korean government and financial targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 603deb15153a715e2b73aef3857d758… 2025-09-22 2025-09-22
HASH efa3c987532cc0bdac533845ad8df5ea 2025-09-22 2025-09-22
HASH d03deb92153a71458973aef3857d75b… 2025-09-22 2025-09-22
EMAIL [email protected] 2025-09-22 2025-09-22
EMAIL [email protected] 2025-09-22 2025-09-22
URL https://mail.yonsei.ac.kr/commo… 2025-09-22 2025-09-22
DOMAIN amiunique.org 2025-09-22 2025-09-22
DOMAIN togoogle.com 2025-09-22 2025-09-22
DOMAIN service.navers.org 2025-09-22 2025-09-22
DOMAIN toftp.fu-berlin.de 2025-09-22 2025-09-22
DOMAIN ongoogle.com 2025-09-22 2025-09-22
DOMAIN acfun.cn 2025-09-22 2025-09-22
DOMAIN payload.info 2025-09-22 2025-09-22
IPv4 45.133.194.126 2025-09-22 2025-09-22
IPv4 45.133.194.88 2025-09-22 2025-09-22
DOMAIN nid.navermails.com 2025-09-01 2025-09-22
DOMAIN nid-security.com 2025-08-22 2025-09-22
IPv4 203.234.192.200 2025-08-15 2025-09-22
IPv4 27.255.80.170 2023-11-01 2025-09-22

Related Actors

Related Reports

« Back