Larva-25010 - APT Down 공격자 PC 분석
2025-10-02 • Ahnlab • Larva-25010 - Analysis of the APT Down attacker PC •
AhnLab reviewed public data from “APT Down: the North Korea Files” and related disclosures about an attacker workstation that the original authors claimed belonged to a Kimsuky member. The material describes sustained intrusions against South Korean administrative agencies, military organizations, and telecommunications targets, with additional reconnaissance activity aimed at Taiwan and Japan. The excerpt links the activity to credential and certificate exposure, possible shared government passwords, phishing preparation for Naver and Kakao login pages, and tools or techniques including Ivanti exploitation, syslogk, Tinyshell, phishing, and Cobalt Strike. Listed indicators include multiple file hashes, the domain websecuritynotices[.]com, and IP address 104[.]167[.]16[.]97, making the report useful for defenders tracking exposed infrastructure and intrusion artifacts tied to the APT Down dataset.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3b76316810d61e114015af617c5d0408 | 2025-10-02 | 2025-10-02 |
| HASH | 00dfce9ad207f77397dbbb6791d64a9e | 2025-10-02 | 2025-10-02 |
| HASH | 36d2be6eb548aee37852f7fbf38dcf30 | 2025-10-02 | 2025-10-02 |
| HASH | 2c0fbdb97439e079bbd8919c39598508 | 2025-10-02 | 2025-10-02 |
| HASH | 1d475427100ad95edca070d75fa3b267 | 2025-10-02 | 2025-10-02 |
| IPv4 | 104.167.16.97 | 2025-10-02 | 2025-10-02 |
| DOMAIN | websecuritynotices.com | 2025-08-22 | 2025-10-02 |