Larva-25010 - APT Down 공격자 PC 분석

2025-10-02 Ahnlab Larva-25010 - Analysis of the APT Down attacker PC

https://asec.ahnlab.com/ko/90408/

Thumbnail for Larva-25010 - APT Down 공격자 PC 분석

AhnLab reviewed public data from “APT Down: the North Korea Files” and related disclosures about an attacker workstation that the original authors claimed belonged to a Kimsuky member. The material describes sustained intrusions against South Korean administrative agencies, military organizations, and telecommunications targets, with additional reconnaissance activity aimed at Taiwan and Japan. The excerpt links the activity to credential and certificate exposure, possible shared government passwords, phishing preparation for Naver and Kakao login pages, and tools or techniques including Ivanti exploitation, syslogk, Tinyshell, phishing, and Cobalt Strike. Listed indicators include multiple file hashes, the domain websecuritynotices[.]com, and IP address 104[.]167[.]16[.]97, making the report useful for defenders tracking exposed infrastructure and intrusion artifacts tied to the APT Down dataset.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3b76316810d61e114015af617c5d0408 2025-10-02 2025-10-02
HASH 00dfce9ad207f77397dbbb6791d64a9e 2025-10-02 2025-10-02
HASH 36d2be6eb548aee37852f7fbf38dcf30 2025-10-02 2025-10-02
HASH 2c0fbdb97439e079bbd8919c39598508 2025-10-02 2025-10-02
HASH 1d475427100ad95edca070d75fa3b267 2025-10-02 2025-10-02
IPv4 104.167.16.97 2025-10-02 2025-10-02
DOMAIN websecuritynotices.com 2025-08-22 2025-10-02

Related Actors

Related Reports

« Back