Kimsuky Hackers Create Phishing Site Mimicking Korea University: Are They Targeting Entire Research Institutions?
2024-07-24 • Criminal IP •
If this phishing site is indeed the work of Kimsuky and linked to North Korea, targeting institutions that share state information might be a more accessible approach than directly hacking national institutions. Hacker Targeting Educational Institutions, Suspected to be North Korean Kimsuky The primary target of this phishing site is major university portals in South Korea. The North Korean hacking group Kimsuky has sparked controversy by reportedly developing a phishing site disguised as the Korea University portal. This is a well-known issue in the security industry, where experts frequently remark that “schools are always vulnerable, but nothing is done due to lack of funds.” Concrete evidence linking Kimsuky to this phishing site has not yet surfaced.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://www.ucloud.cn | 2024-07-24 | 2024-07-24 |