Kimsuky Group: Track the King of the Spear-Phishing
2019-10-04 • FSI •
https://www.virusbulletin.com/uploads/pdf/conference_slides/2019/VB2019-Kim.pdf
Attachments
VB2019-Kim.pdf (26 MB)
The Financial Security Institute presentation tracks Kimsuky as a North Korea-linked spear-phishing actor active since at least 2013 and still operating in 2019, targeting infrastructure, government, North Korean defectors, politicians, diplomatic and human-rights organizations for intelligence collection and social disruption. It catalogs the group’s server-side phishing toolchain—mailer components, beacons, phishing pages and loggers—alongside malicious HWP and camouflaged documents, scripts, downloaders and info-stealers used to deliver payloads and harvest accounts or host information. Case studies show defenders using the actor’s OPSEC failures, including directory listing, leaked FTP credentials and file-download vulnerabilities, to discover malware, mailer infrastructure and C2 relationships such as suppcrt-seourity[.]esy.es, member-authorize[.]com, ddlovke[.]kr and military[.]co.kr. The slides emphasize proactive tracking and cooperation with relevant agencies because monitoring attacker infrastructure exposed new malware, server-side toolkits and links between compromised Korean sites and hosting services.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | member-authorize.com | 2019-10-04 | 2020-11-12 |
| IPv4 | 185.224.138.29 | 2019-03-04 | 2020-11-12 |
| HASH | 53ac231e8091abcd0978124f9268b4e4 | 2019-10-04 | 2019-10-04 |
| HASH | 8b59ea1ee28e0123da82801abc0cce4d | 2019-10-04 | 2019-10-04 |
| DOMAIN | ddlove.kr | 2019-10-04 | 2019-10-04 |
| DOMAIN | ddlovke.kr | 2019-10-04 | 2019-10-04 |
| DOMAIN | military.co.kr | 2019-10-04 | 2019-10-04 |
| IPv4 | 211.202.2.51 | 2019-10-04 | 2019-10-04 |
| HASH | f22db1e3ea74af791e34ad5aa0297664 | 2019-03-04 | 2019-10-04 |
| HASH | 4de21c3af64b3b605446278de92dfff4 | 2019-03-04 | 2019-10-04 |
| DOMAIN | gyjmc.com | 2019-01-30 | 2019-10-04 |