Kimsuky(김수키) 비트코인 주소 추적

2023-06-07 Plainbit Kimsuky Bitcoin Address Tracking

https://blog.plainbit.co.kr/kimsuky-bitcoin-address-tracking/

Thumbnail for Kimsuky(김수키) 비트코인 주소 추적

Plainbit analyzed two Bitcoin addresses publicly associated with Kimsuky in the June 2023 Korea-US joint advisory and traced their transaction behavior with QLUE. One address received small payments mostly from Upbit-linked sources and later sent change to addresses identified as Lazarus, while downstream funds moved through complex peel-chain patterns involving services such as Bitzlato, WhiteBIT, Paxful, FTX, and F2Pool/discus_fish. The second address received funds from an unidentified cluster, sent one transaction to a Lazarus-identified address, and then moved funds through similarly complex peel chains involving Binance, Bitzlato, Paxful, WhiteBIT, Payeer, Freewallet, LBank, and CoinPayments. The report concludes that the observed flows suggest operational linkage between Kimsuky- and Lazarus-tagged wallets and show DPRK-linked laundering behavior designed to complicate tracing without relying on CoinJoin.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN totalcoin.io 2023-06-07 2023-06-07
DOMAIN freewallet.org 2023-06-07 2023-06-07

Related Actors

Related Reports

« Back