Kimsuky/APT43 Phishing Infrastructure: A Technical Evolution
2025-09-30 • Siddhant •
Leaked Apache access, error, virtual-host, and configuration logs reconstruct Kimsuky/APT43 phishing infrastructure used against South Korean government and military targets in 2025. The operators staged domains including sponetcloud.com and websecuritynotices.com on an Ubuntu server running Apache and PHP, with Lets Encrypt certificates and a reverse-proxy configuration that exposed localhost-backed traffic in the logs. Early January entries show TLS and server-setup testing months before the campaign, while May activity from the 79.110.55.0/24 range shows development and testing of generator.php and request.php components. The evidence gives defenders concrete infrastructure, operator IP ranges, server configuration artifacts, and development errors to hunt for related Kimsuky phishing operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | websecuritynotices.com | 2025-08-22 | 2025-10-02 |
| URL | https://download.sponetcloud.co… | 2025-09-30 | 2025-09-30 |
| URL | https://websecuritynotices.com/… | 2025-09-30 | 2025-09-30 |
| URL | https://www.websecuritynotices.… | 2025-09-30 | 2025-09-30 |
| URL | https://download.sponetcloud.co… | 2025-09-30 | 2025-09-30 |
| URL | https://www.websecuritynotices.… | 2025-09-30 | 2025-09-30 |
| DOMAIN | download.sponetcloud.com | 2025-09-30 | 2025-09-30 |
| DOMAIN | sponetcloud.com | 2025-09-30 | 2025-09-30 |
| IPv4 | 149.87.155.12 | 2025-09-30 | 2025-09-30 |
| IPv4 | 210.117.199.101 | 2025-09-30 | 2025-09-30 |
| IPv4 | 79.110.55.3 | 2025-09-30 | 2025-09-30 |
| IPv4 | 79.110.55.5 | 2025-09-30 | 2025-09-30 |
| IPv4 | 52.228.152.193 | 2025-09-30 | 2025-09-30 |
| IPv4 | 47.236.172.160 | 2025-09-30 | 2025-09-30 |
| IPv4 | 79.110.55.14 | 2025-09-30 | 2025-09-30 |
| IPv4 | 79.110.55.10 | 2025-09-30 | 2025-09-30 |
| IPv4 | 185.194.178.6 | 2025-09-30 | 2025-09-30 |
| IPv4 | 79.110.55.11 | 2025-09-30 | 2025-09-30 |
| IPv4 | 1.221.137.163 | 2025-09-30 | 2025-09-30 |
| IPv4 | 185.194.178.17 | 2025-09-30 | 2025-09-30 |
| IPv4 | 194.50.16.252 | 2025-09-30 | 2025-09-30 |
| IPv4 | 185.219.141.231 | 2025-09-30 | 2025-09-30 |