Kimsuky APT Data Leak: Inside DPRK Cyber Espionage Tools

2025-08-22 Foresiet

https://foresiet.com/blog/kimsuky-apt-data-leak/

Thumbnail for Kimsuky APT Data Leak: Inside DPRK Cyber Espionage Tools

A leaked operational dump attributed in the source to North Korea’s Kimsuky exposed virtual machine images, VPS data, phishing kits, rootkits, credentials, browser history, and operator infrastructure. The material shows phishing activity against South Korean government and defense-related entities, including DCC-linked domains, the Supreme Prosecutor’s Office, korea.kr, Daum, Kakao, and Naver, plus evidence suggesting compromise of South Korea’s Foreign Ministry email-platform source code. The tooling described includes a Linux kernel rootkit, a personalized Cobalt Strike Beacon, Ivanti exploit material tied to CVE-2025-0282, CVE-2025-0283, and CVE-2025-22457, Bushfire, SpawnChimera, phishing generators, and evasion logic for security crawlers. The leak matters because it provides unusually direct evidence of Kimsuky’s operational tradecraft, credential reuse, persistence mechanisms, covert C2 methods, and targeting of South Korean defense, diplomatic, media, and public-sector infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN websecuritynotices.com 2025-08-22 2025-10-02
DOMAIN nid-security.com 2025-08-22 2025-09-22
IPv4 203.234.192.200 2025-08-15 2025-09-22
DOMAIN monovm.com 2025-08-22 2025-08-22
DOMAIN sg24.vps.bz 2025-08-22 2025-08-22
DOMAIN xakep.ru 2025-08-22 2025-08-22
DOMAIN ak.com 2025-08-22 2025-08-22
DOMAIN by.com 2025-08-22 2025-08-22
DOMAIN il.com 2025-08-22 2025-08-22

Related Actors

Related Reports

« Back