Kimsuky Group: Track the King of the Spear-Phishing

2019-10-04 FSI

https://www.virusbulletin.com/uploads/pdf/conference_slides/2019/VB2019-Kim.pdf

Attachments

VB2019-Kim.pdf (26 MB)

Thumbnail for Kimsuky Group: Track the King of the Spear-Phishing

The Financial Security Institute presentation tracks Kimsuky as a North Korea-linked spear-phishing actor active since at least 2013 and still operating in 2019, targeting infrastructure, government, North Korean defectors, politicians, diplomatic and human-rights organizations for intelligence collection and social disruption. It catalogs the group’s server-side phishing toolchain—mailer components, beacons, phishing pages and loggers—alongside malicious HWP and camouflaged documents, scripts, downloaders and info-stealers used to deliver payloads and harvest accounts or host information. Case studies show defenders using the actor’s OPSEC failures, including directory listing, leaked FTP credentials and file-download vulnerabilities, to discover malware, mailer infrastructure and C2 relationships such as suppcrt-seourity[.]esy.es, member-authorize[.]com, ddlovke[.]kr and military[.]co.kr. The slides emphasize proactive tracking and cooperation with relevant agencies because monitoring attacker infrastructure exposed new malware, server-side toolkits and links between compromised Korean sites and hosting services.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN member-authorize.com 2019-10-04 2020-11-12
IPv4 185.224.138.29 2019-03-04 2020-11-12
HASH 53ac231e8091abcd0978124f9268b4e4 2019-10-04 2019-10-04
HASH 8b59ea1ee28e0123da82801abc0cce4d 2019-10-04 2019-10-04
DOMAIN ddlove.kr 2019-10-04 2019-10-04
DOMAIN ddlovke.kr 2019-10-04 2019-10-04
DOMAIN military.co.kr 2019-10-04 2019-10-04
IPv4 211.202.2.51 2019-10-04 2019-10-04
HASH f22db1e3ea74af791e34ad5aa0297664 2019-03-04 2019-10-04
HASH 4de21c3af64b3b605446278de92dfff4 2019-03-04 2019-10-04
DOMAIN gyjmc.com 2019-01-30 2019-10-04

Related Actors

Related Reports

2026-04-17 • 60% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing
« Back