Kimsuky APT continues to target South Korean government using AppleSeed backdoor
2021-06-01 • Malwarebytes •
Malwarebytes tracked Kimsuky, also known as Thallium, Black Banshee, and Velvet Chollima, using phishing sites, malicious documents, and scripts against high-profile South Korean government targets. One lure translated as “Ministry of Foreign Affairs Edition 2021-05-07,” and the victim set included South Korean foreign-affairs officials and related diplomatic roles. The actor built credential-harvesting pages that mimicked Google, Gmail, Yahoo, and other services, adapted pages for Korean or English users, and used Twitter and Gmail accounts to research targets and register infrastructure. The same infrastructure was reused for AppleSeed command-and-control, with Windows and Android backdoors sharing command patterns and C2 resources such as riseknite.life, ikpoo.cf, travelmountain.ml, and letterpaper.press domains.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 58.229.208.146 | 2021-06-01 | 2025-09-14 |
| IPv4 | 27.102.114.89 | 2021-06-01 | 2023-11-01 |
| IPv4 | 27.102.107.63 | 2021-06-01 | 2023-11-01 |
| [email protected] | 2021-06-01 | 2021-06-01 | |
| URL | http://myaccount.google.nkaac.n… | 2021-06-01 | 2021-06-01 |
| URL | https://signin.gmrail.ml | 2021-06-01 | 2021-06-01 |
| URL | https://accounts.grnail-signing… | 2021-06-01 | 2021-06-01 |
| URL | https://signin.grnail-login.ml | 2021-06-01 | 2021-06-01 |
| URL | https://protect.grnail-signin.g… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccount.google-signin… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccounts-gmail.autho.… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccount.grnail-securi… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccounts.grnail-signi… | 2021-06-01 | 2021-06-01 |
| URL | http://accounts.goggle.hol.es/M… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccount.grnail-signin… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccount.grnail-signin… | 2021-06-01 | 2021-06-01 |
| URL | https://login.gmeil.kro.kr | 2021-06-01 | 2021-06-01 |
| URL | https://accounts.google-manager… | 2021-06-01 | 2021-06-01 |
| URL | https://accounts.grnail-signin.… | 2021-06-01 | 2021-06-01 |
| URL | http://myaccount.google.newkda.… | 2021-06-01 | 2021-06-01 |
| URL | https://myaccount.google.newkda… | 2021-06-01 | 2021-06-01 |
| URL | https://account.googgle.kro.kr | 2021-06-01 | 2021-06-01 |
| URL | https://login.gmail-account.gq | 2021-06-01 | 2021-06-01 |
| URL | https://accounts.google-signin.… | 2021-06-01 | 2021-06-01 |
| URL | https://account.grnail-signin.g… | 2021-06-01 | 2021-06-01 |
| URL | http://myaccounts-gmail.kr-info… | 2021-06-01 | 2021-06-01 |
| URL | http://myaccount.cgmail.pe.hu/s… | 2021-06-01 | 2021-06-01 |
| DOMAIN | accounts.grnail-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | signin.gmrail.ml | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.google.newkda.com | 2021-06-01 | 2021-06-01 |
| DOMAIN | accounts.google-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | account.grnail-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.google.nkaac.net | 2021-06-01 | 2021-06-01 |
| DOMAIN | login.gmeil.kro.kr | 2021-06-01 | 2021-06-01 |
| DOMAIN | accounts.grnail-signing.work | 2021-06-01 | 2021-06-01 |
| DOMAIN | signin.grnail-login.ml | 2021-06-01 | 2021-06-01 |
| DOMAIN | login.gmail-account.gq | 2021-06-01 | 2021-06-01 |
| DOMAIN | accounts.goggle.hol.es | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.grnail-signing.work | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccounts-gmail.kr-infos.com | 2021-06-01 | 2021-06-01 |
| DOMAIN | accounts.google-manager.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.google-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.cgmail.pe.hu | 2021-06-01 | 2021-06-01 |
| DOMAIN | account.googgle.kro.kr | 2021-06-01 | 2021-06-01 |
| DOMAIN | protect.grnail-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccounts.grnail-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccounts-gmail.autho.co | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.grnail-signin.ga | 2021-06-01 | 2021-06-01 |
| DOMAIN | myaccount.grnail-security.work | 2021-06-01 | 2021-06-01 |
| IPv4 | 210.16.121.137 | 2021-06-01 | 2021-06-01 |
| IPv4 | 45.58.55.73 | 2021-06-01 | 2021-06-01 |
| IPv4 | 216.189.157.89 | 2021-06-01 | 2021-06-01 |
| IPv4 | 210.16.120.34 | 2021-06-01 | 2021-06-01 |
| IPv4 | 45.13.135.103 | 2020-03-04 | 2021-06-01 |