Kimsuky의 Quishing 캠페인
2026-01-20 • Piolink • Kimsuky Quishing campaign •
https://www.piolink.com/kr/service/Security-Analysis.php?bbsCode=security&vType=view&idx=187&page=1
Kimsuky is described using malicious QR codes in spearphishing emails to move victims from managed desktops to less-protected mobile devices and evade URL inspection and sandboxing. The campaign targets think tanks, academic institutions, government-related entities, policy experts, and strategic advisory firms with lures impersonating foreign advisers, embassy staff, internal colleagues, and conference organizers. QR scans lead to attacker-controlled infrastructure, mobile-optimized credential phishing pages for services such as Microsoft 365, VPN portals, and Google accounts, and in a Korean logistics-themed case to Android malware delivery through SecDelivery.apk. The report lists infrastructure including 27.102.137[.]181, 27.102.137[.]106, several related hosts, phishing URLs, and hashes, showing how credential theft, mobile device compromise, and social engineering are combined against DPRK-policy communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://delivery.cjlogistics.kr… | 2026-01-20 | 2026-01-20 |
| HASH | 27ea7ef88724c51bbe3ad42853bbc204 | 2025-12-16 | 2026-01-20 |
| HASH | 858588b7c5331c948fb3e84d9b4ddbb7 | 2025-12-16 | 2026-01-20 |
| HASH | c90ee7d3b1226f73044e7ae635493d31 | 2025-12-16 | 2026-01-20 |
| HASH | 86da5e00a9c73c9cb0855805cbc38c4a | 2025-12-16 | 2026-01-20 |
| HASH | 436287ad0ea3a9e94cd4574d54d0dec5 | 2025-12-16 | 2026-01-20 |
| HASH | 36677d732da69b7a81a46f9a06c36260 | 2025-12-16 | 2026-01-20 |
| HASH | 506e136336ca9d7246caf8c9011fe97e | 2025-12-16 | 2026-01-20 |
| HASH | 3a2a9f205c79ee45a84e3d862884fd72 | 2025-12-16 | 2026-01-20 |
| HASH | 2a7dab4c0f6507bc5fd826f9a336d50c | 2025-12-16 | 2026-01-20 |
| HASH | 2b99603cd8e69f82c064856d6ff63996 | 2025-12-16 | 2026-01-20 |
| HASH | 03a117c6cb86859623720e75f839260a | 2025-12-16 | 2026-01-20 |
| URL | https://delivery.cjlogistics.kr… | 2025-12-16 | 2026-01-20 |
| DOMAIN | delivery.cjlogistics.kro.kr | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.181 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.138.163 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.138.181 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.106 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.93 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.180 | 2025-12-16 | 2026-01-20 |
| IPv4 | 27.102.137.214 | 2025-12-16 | 2026-01-20 |