Inside the Kimsuky Leak: How the “Kim” Dump Exposed North Korea’s Credential Theft Playbook

2025-09-05 Domaintools

https://dti.domaintools.com/inside-the-kimsuky-leak-how-the-kim-dump-exposed-north-koreas-credential-theft-playbook/

Thumbnail for Inside the Kimsuky Leak: How the “Kim” Dump Exposed North Korea’s Credential Theft Playbook

DomainTools examines the “Kim” dump as a rare operational leak tied in the text to Kimsuky/APT43 and North Korean-aligned credential theft activity. The material shows South Korean and Taiwanese targeting through phishing domains, AiTM credential capture, OCR processing of Korean PKI and VPN documents, PAM password-change logs, and reconnaissance of government, academic, and developer assets. Credential theft is central: the dump includes South Korean GPKI-style .key material, plaintext passwords, and privileged accounts such as oracle, svradmin, and app_adm01. Malware-development artifacts include NASM shellcode compilation, Win32 API hash obfuscation, references to public offensive tooling, proxy configuration probing, and a Linux rootkit using syscall hooking and stealth persistence under paths such as /usr/lib64/tracker-fs. The report is significant because it connects phishing infrastructure, privileged credential access, malware tooling, and possible Chinese-language resource use into a single view of the operator’s playbook.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN tw.systexcloud.com 2025-09-05 2025-09-26
IPv4 59.125.159.81 2025-09-05 2025-09-26
IPv4 118.163.30.45 2025-09-05 2025-09-26
IPv4 163.29.3.119 2025-09-05 2025-09-26
DOMAIN nid-security.com 2025-08-22 2025-09-22
DOMAIN dtc-tpe.com 2025-09-05 2025-09-05
DOMAIN caa.org 2025-09-05 2025-09-05
DOMAIN wuzak.com 2025-09-05 2025-09-05
DOMAIN html-load.com 2025-09-05 2025-09-05
DOMAIN mlogin.mdfapps.com 2025-09-05 2025-09-05
DOMAIN koala-app.com 2025-09-05 2025-09-05
DOMAIN webcloud-notice.com 2025-09-05 2025-09-05
IPv4 122.114.233.77 2025-09-05 2025-09-05
IPv4 118.163.30.46 2025-09-05 2025-09-05
IPv4 218.92.0.210 2025-09-05 2025-09-05
IPv4 23.95.213.210 2025-09-05 2025-09-05
IPv4 59.125.159.254 2025-09-05 2025-09-05
DOMAIN zhihu.com 2022-01-31 2025-09-05

Related Actors

Related Reports

« Back