Kimsuky(김수키) 비트코인 주소 추적
2023-06-07 • Plainbit • Kimsuky Bitcoin Address Tracking •
https://blog.plainbit.co.kr/kimsuky-bitcoin-address-tracking/
Plainbit analyzed two Bitcoin addresses publicly associated with Kimsuky in the June 2023 Korea-US joint advisory and traced their transaction behavior with QLUE. One address received small payments mostly from Upbit-linked sources and later sent change to addresses identified as Lazarus, while downstream funds moved through complex peel-chain patterns involving services such as Bitzlato, WhiteBIT, Paxful, FTX, and F2Pool/discus_fish. The second address received funds from an unidentified cluster, sent one transaction to a Lazarus-identified address, and then moved funds through similarly complex peel chains involving Binance, Bitzlato, Paxful, WhiteBIT, Payeer, Freewallet, LBank, and CoinPayments. The report concludes that the observed flows suggest operational linkage between Kimsuky- and Lazarus-tagged wallets and show DPRK-linked laundering behavior designed to complicate tracing without relying on CoinJoin.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | totalcoin.io | 2023-06-07 | 2023-06-07 |
| DOMAIN | freewallet.org | 2023-06-07 | 2023-06-07 |