"Million OK!!!!" and the Naver Facade: Tracking Recent Suspected Kimsuky Infrastructure

2024-12-10 Hunt.io

https://hunt.io/blog/million-ok-naver-facade-kimsuky-tracking

Thumbnail for "Million OK!!!!" and the Naver Facade: Tracking Recent Suspected Kimsuky Infrastructure

Hunt observed infrastructure returning the distinctive HTTP response "Million OK !!!!" and linked the activity to suspected Kimsuky operations through recurring domains, hosting patterns, and Naver-themed phishing traits. The infrastructure used Naver favicons and domains under TLDs such as p-e.kr, o-r.kr, and n-e.kr, reflecting repeated targeting of South Korean Naver users for credential theft. Several observed IPs were hosted on UCLOUD Information Technology in South Korea, with some servers exposing Sectigo TLS certificates and an older Apache/OpenSSL/PHP stack. One certificate common name, edoc-send.n-e.kr, and a related registrant email connected the activity to infrastructure previously reported with KLogEXE and FPSpy, giving defenders additional pivots for monitoring suspected Kimsuky phishing and C2 assets.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN o-r.kr 2023-05-24 2026-06-01
DOMAIN n-e.kr 2022-08-26 2026-06-01
DOMAIN p-e.kr 2021-12-21 2026-06-01
EMAIL [email protected] 2024-12-10 2026-04-17
IPv4 123.58.200.13 2024-12-10 2026-04-17
IPv4 118.193.69.248 2024-12-10 2026-04-17
IPv4 123.58.200.50 2024-12-10 2026-04-17
IPv4 118.193.68.146 2024-12-10 2026-04-17
IPv4 101.36.114.153 2024-12-10 2026-04-17
IPv4 152.32.243.184 2024-12-10 2026-04-17
IPv4 152.32.138.191 2024-12-10 2026-04-17
IPv4 118.194.248.148 2024-12-10 2026-04-17
IPv4 152.32.138.63 2024-12-10 2026-04-17
IPv4 152.32.243.153 2024-12-10 2026-04-17
HASH 974e386f8facff325ec2f3ebb7439a9… 2024-12-10 2024-12-10
HASH 5f2c65e695d85395634e7ab56124242… 2024-12-10 2024-12-10
HASH 98c85ef91e05593cd470ffe8698aa6d… 2024-12-10 2024-12-10
HASH d8a8ddda6cc12c5533268b20e48e1b6… 2024-12-10 2024-12-10
HASH 393cbd41f14b1c55bde92a32e10b5d6… 2024-12-10 2024-12-10
DOMAIN checkmail.kro.kr 2024-12-10 2024-12-10
DOMAIN nidcheck.o-r.kr 2024-12-10 2024-12-10
DOMAIN nld.blog-view.o-r.kr 2024-12-10 2024-12-10
DOMAIN edoc-send.n-e.kr 2024-12-10 2024-12-10
DOMAIN nidauth.r-e.kr 2024-12-10 2024-12-10

Related Actors

Related Reports

2026-04-17 • 78% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing • Shares 11 IOCs
« Back