In-Depth Analysis of the APT Down - The North Korea Files leak
2025-09-22 • ENKI •
The leaked “APT Down - The North Korea Files” material exposed a Deepin workstation dump and VPS data containing malware source code, attack tools, exfiltrated material, and phishing infrastructure tied by the authors to activity against South Korea. ENKI found rootkit source code matching a rootkit from its 2022 investigation at a South Korean financial institution, including identical logic and encryption material, plus an updated 2025 version. The tooling includes a syslogk Linux rootkit and companion backdoor that hide processes, ports, and directories, use Netfilter hooks and magic-packet triggering, support command execution, file transfer, and proxying, and mask traffic as common protocols. The leak also contained an Ivanti 1-day exploit, apparent Ministry of Foreign Affairs and GPKISecureWebX source code, and spear-phishing evidence targeting entities such as the Public Prosecutor’s Office and Defense Counterintelligence Command, indicating sustained operations against South Korean government and financial targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 603deb15153a715e2b73aef3857d758… | 2025-09-22 | 2025-09-22 |
| HASH | efa3c987532cc0bdac533845ad8df5ea | 2025-09-22 | 2025-09-22 |
| HASH | d03deb92153a71458973aef3857d75b… | 2025-09-22 | 2025-09-22 |
| [email protected] | 2025-09-22 | 2025-09-22 | |
| [email protected] | 2025-09-22 | 2025-09-22 | |
| URL | https://mail.yonsei.ac.kr/commo… | 2025-09-22 | 2025-09-22 |
| DOMAIN | amiunique.org | 2025-09-22 | 2025-09-22 |
| DOMAIN | togoogle.com | 2025-09-22 | 2025-09-22 |
| DOMAIN | service.navers.org | 2025-09-22 | 2025-09-22 |
| DOMAIN | toftp.fu-berlin.de | 2025-09-22 | 2025-09-22 |
| DOMAIN | ongoogle.com | 2025-09-22 | 2025-09-22 |
| DOMAIN | acfun.cn | 2025-09-22 | 2025-09-22 |
| DOMAIN | payload.info | 2025-09-22 | 2025-09-22 |
| IPv4 | 45.133.194.126 | 2025-09-22 | 2025-09-22 |
| IPv4 | 45.133.194.88 | 2025-09-22 | 2025-09-22 |
| DOMAIN | nid.navermails.com | 2025-09-01 | 2025-09-22 |
| DOMAIN | nid-security.com | 2025-08-22 | 2025-09-22 |
| IPv4 | 203.234.192.200 | 2025-08-15 | 2025-09-22 |
| IPv4 | 27.255.80.170 | 2023-11-01 | 2025-09-22 |