Inside the Kimsuky Leak: How the “Kim” Dump Exposed North Korea’s Credential Theft Playbook
2025-09-05 • Domaintools •
DomainTools examines the “Kim” dump as a rare operational leak tied in the text to Kimsuky/APT43 and North Korean-aligned credential theft activity. The material shows South Korean and Taiwanese targeting through phishing domains, AiTM credential capture, OCR processing of Korean PKI and VPN documents, PAM password-change logs, and reconnaissance of government, academic, and developer assets. Credential theft is central: the dump includes South Korean GPKI-style .key material, plaintext passwords, and privileged accounts such as oracle, svradmin, and app_adm01. Malware-development artifacts include NASM shellcode compilation, Win32 API hash obfuscation, references to public offensive tooling, proxy configuration probing, and a Linux rootkit using syscall hooking and stealth persistence under paths such as /usr/lib64/tracker-fs. The report is significant because it connects phishing infrastructure, privileged credential access, malware tooling, and possible Chinese-language resource use into a single view of the operator’s playbook.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | tw.systexcloud.com | 2025-09-05 | 2025-09-26 |
| IPv4 | 59.125.159.81 | 2025-09-05 | 2025-09-26 |
| IPv4 | 118.163.30.45 | 2025-09-05 | 2025-09-26 |
| IPv4 | 163.29.3.119 | 2025-09-05 | 2025-09-26 |
| DOMAIN | nid-security.com | 2025-08-22 | 2025-09-22 |
| DOMAIN | dtc-tpe.com | 2025-09-05 | 2025-09-05 |
| DOMAIN | caa.org | 2025-09-05 | 2025-09-05 |
| DOMAIN | wuzak.com | 2025-09-05 | 2025-09-05 |
| DOMAIN | html-load.com | 2025-09-05 | 2025-09-05 |
| DOMAIN | mlogin.mdfapps.com | 2025-09-05 | 2025-09-05 |
| DOMAIN | koala-app.com | 2025-09-05 | 2025-09-05 |
| DOMAIN | webcloud-notice.com | 2025-09-05 | 2025-09-05 |
| IPv4 | 122.114.233.77 | 2025-09-05 | 2025-09-05 |
| IPv4 | 118.163.30.46 | 2025-09-05 | 2025-09-05 |
| IPv4 | 218.92.0.210 | 2025-09-05 | 2025-09-05 |
| IPv4 | 23.95.213.210 | 2025-09-05 | 2025-09-05 |
| IPv4 | 59.125.159.254 | 2025-09-05 | 2025-09-05 |
| DOMAIN | zhihu.com | 2022-01-31 | 2025-09-05 |