"Million OK!!!!" and the Naver Facade: Tracking Recent Suspected Kimsuky Infrastructure
2024-12-10 • Hunt.io •
https://hunt.io/blog/million-ok-naver-facade-kimsuky-tracking
Hunt observed infrastructure returning the distinctive HTTP response "Million OK !!!!" and linked the activity to suspected Kimsuky operations through recurring domains, hosting patterns, and Naver-themed phishing traits. The infrastructure used Naver favicons and domains under TLDs such as p-e.kr, o-r.kr, and n-e.kr, reflecting repeated targeting of South Korean Naver users for credential theft. Several observed IPs were hosted on UCLOUD Information Technology in South Korea, with some servers exposing Sectigo TLS certificates and an older Apache/OpenSSL/PHP stack. One certificate common name, edoc-send.n-e.kr, and a related registrant email connected the activity to infrastructure previously reported with KLogEXE and FPSpy, giving defenders additional pivots for monitoring suspected Kimsuky phishing and C2 assets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | o-r.kr | 2023-05-24 | 2026-06-01 |
| DOMAIN | n-e.kr | 2022-08-26 | 2026-06-01 |
| DOMAIN | p-e.kr | 2021-12-21 | 2026-06-01 |
| [email protected] | 2024-12-10 | 2026-04-17 | |
| IPv4 | 123.58.200.13 | 2024-12-10 | 2026-04-17 |
| IPv4 | 118.193.69.248 | 2024-12-10 | 2026-04-17 |
| IPv4 | 123.58.200.50 | 2024-12-10 | 2026-04-17 |
| IPv4 | 118.193.68.146 | 2024-12-10 | 2026-04-17 |
| IPv4 | 101.36.114.153 | 2024-12-10 | 2026-04-17 |
| IPv4 | 152.32.243.184 | 2024-12-10 | 2026-04-17 |
| IPv4 | 152.32.138.191 | 2024-12-10 | 2026-04-17 |
| IPv4 | 118.194.248.148 | 2024-12-10 | 2026-04-17 |
| IPv4 | 152.32.138.63 | 2024-12-10 | 2026-04-17 |
| IPv4 | 152.32.243.153 | 2024-12-10 | 2026-04-17 |
| HASH | 974e386f8facff325ec2f3ebb7439a9… | 2024-12-10 | 2024-12-10 |
| HASH | 5f2c65e695d85395634e7ab56124242… | 2024-12-10 | 2024-12-10 |
| HASH | 98c85ef91e05593cd470ffe8698aa6d… | 2024-12-10 | 2024-12-10 |
| HASH | d8a8ddda6cc12c5533268b20e48e1b6… | 2024-12-10 | 2024-12-10 |
| HASH | 393cbd41f14b1c55bde92a32e10b5d6… | 2024-12-10 | 2024-12-10 |
| DOMAIN | checkmail.kro.kr | 2024-12-10 | 2024-12-10 |
| DOMAIN | nidcheck.o-r.kr | 2024-12-10 | 2024-12-10 |
| DOMAIN | nld.blog-view.o-r.kr | 2024-12-10 | 2024-12-10 |
| DOMAIN | edoc-send.n-e.kr | 2024-12-10 | 2024-12-10 |
| DOMAIN | nidauth.r-e.kr | 2024-12-10 | 2024-12-10 |