Kimsuky Phishing Operations Putting In Work

2020-09-28 Threatconnect

http://web.archive.org/web/20201103192938/https://threatconnect.com/blog/kimsuky-phishing-operations-putting-in-work/

Thumbnail for Kimsuky Phishing Operations Putting In Work

ThreatConnect believes that Kimsuky will continue to target journalism and civil society organizations, particularly those focusing on North Korean issues. Researching both the attacker’s infrastructure and tooling, we believe the nexus of the attack to be DPRK’s Kimsuky group (aka Velvet Chollima). Organizations reporting on North Korea human rights violations or working with North Korean defectors need to remain especially vigilant of phishing attacks that take advantage of the information sharing culture they are part of. Kimsuky is notorious for their phishing efforts; researchers even dubbed this group the “King of Spear Phishing” in a 2019 VirusBulletin paper.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 252d1b7a379f97fddd691880c1cf93e… 2020-09-28 2020-11-02
URL http://wave.posadadesantiago.co… 2020-09-28 2020-11-02
DOMAIN wave.posadadesantiago.com 2020-09-28 2020-11-02
URL http://onedrive.sslport.work/sh… 2020-09-28 2020-09-28
DOMAIN offerhubs.org 2020-09-28 2020-09-28
DOMAIN doc-view.docomo.ne.org 2020-09-28 2020-09-28
DOMAIN preview.manage.org 2020-09-28 2020-09-28
DOMAIN login.yahoo.co.jp.org 2020-09-28 2020-09-28
DOMAIN login.un-phish.bad.com 2020-09-28 2020-09-28
DOMAIN login.aei.org 2020-09-28 2020-09-28
DOMAIN amaniafrica-et.org 2020-09-28 2020-09-28
DOMAIN login.gordonchang.org 2020-09-28 2020-09-28
DOMAIN webmail.org 2020-09-28 2020-09-28
DOMAIN login.microsoftonline.org 2020-09-28 2020-09-28
DOMAIN login.yahoo.com-service.org 2020-09-28 2020-09-28
DOMAIN login-yahoo.org 2020-09-28 2020-09-28
IPv4 108.62.141.33 2020-09-28 2020-09-28

Related Actors

Related Reports

2026-04-17 • 60% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing
« Back