Kimsuky/APT43 Phishing Infrastructure: A Technical Evolution

2025-09-30 Siddhant

https://medium.com/@siddhantalokmishra/kimsuky-apt43-phishing-infrastructure-a-technical-evolution-5b4653c5c99b

Thumbnail for Kimsuky/APT43 Phishing Infrastructure: A Technical Evolution

Leaked Apache access, error, virtual-host, and configuration logs reconstruct Kimsuky/APT43 phishing infrastructure used against South Korean government and military targets in 2025. The operators staged domains including sponetcloud.com and websecuritynotices.com on an Ubuntu server running Apache and PHP, with Lets Encrypt certificates and a reverse-proxy configuration that exposed localhost-backed traffic in the logs. Early January entries show TLS and server-setup testing months before the campaign, while May activity from the 79.110.55.0/24 range shows development and testing of generator.php and request.php components. The evidence gives defenders concrete infrastructure, operator IP ranges, server configuration artifacts, and development errors to hunt for related Kimsuky phishing operations.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN websecuritynotices.com 2025-08-22 2025-10-02
URL https://download.sponetcloud.co… 2025-09-30 2025-09-30
URL https://websecuritynotices.com/… 2025-09-30 2025-09-30
URL https://www.websecuritynotices.… 2025-09-30 2025-09-30
URL https://download.sponetcloud.co… 2025-09-30 2025-09-30
URL https://www.websecuritynotices.… 2025-09-30 2025-09-30
DOMAIN download.sponetcloud.com 2025-09-30 2025-09-30
DOMAIN sponetcloud.com 2025-09-30 2025-09-30
IPv4 149.87.155.12 2025-09-30 2025-09-30
IPv4 210.117.199.101 2025-09-30 2025-09-30
IPv4 79.110.55.3 2025-09-30 2025-09-30
IPv4 79.110.55.5 2025-09-30 2025-09-30
IPv4 52.228.152.193 2025-09-30 2025-09-30
IPv4 47.236.172.160 2025-09-30 2025-09-30
IPv4 79.110.55.14 2025-09-30 2025-09-30
IPv4 79.110.55.10 2025-09-30 2025-09-30
IPv4 185.194.178.6 2025-09-30 2025-09-30
IPv4 79.110.55.11 2025-09-30 2025-09-30
IPv4 1.221.137.163 2025-09-30 2025-09-30
IPv4 185.194.178.17 2025-09-30 2025-09-30
IPv4 194.50.16.252 2025-09-30 2025-09-30
IPv4 185.219.141.231 2025-09-30 2025-09-30

Related Actors

Related Reports

« Back