Kimsuky APT Data Leak: Inside DPRK Cyber Espionage Tools
2025-08-22 • Foresiet •
A leaked operational dump attributed in the source to North Korea’s Kimsuky exposed virtual machine images, VPS data, phishing kits, rootkits, credentials, browser history, and operator infrastructure. The material shows phishing activity against South Korean government and defense-related entities, including DCC-linked domains, the Supreme Prosecutor’s Office, korea.kr, Daum, Kakao, and Naver, plus evidence suggesting compromise of South Korea’s Foreign Ministry email-platform source code. The tooling described includes a Linux kernel rootkit, a personalized Cobalt Strike Beacon, Ivanti exploit material tied to CVE-2025-0282, CVE-2025-0283, and CVE-2025-22457, Bushfire, SpawnChimera, phishing generators, and evasion logic for security crawlers. The leak matters because it provides unusually direct evidence of Kimsuky’s operational tradecraft, credential reuse, persistence mechanisms, covert C2 methods, and targeting of South Korean defense, diplomatic, media, and public-sector infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | websecuritynotices.com | 2025-08-22 | 2025-10-02 |
| DOMAIN | nid-security.com | 2025-08-22 | 2025-09-22 |
| IPv4 | 203.234.192.200 | 2025-08-15 | 2025-09-22 |
| DOMAIN | monovm.com | 2025-08-22 | 2025-08-22 |
| DOMAIN | sg24.vps.bz | 2025-08-22 | 2025-08-22 |
| DOMAIN | xakep.ru | 2025-08-22 | 2025-08-22 |
| DOMAIN | ak.com | 2025-08-22 | 2025-08-22 |
| DOMAIN | by.com | 2025-08-22 | 2025-08-22 |
| DOMAIN | il.com | 2025-08-22 | 2025-08-22 |