Phishing Attack Activities: Threat Actors in Sheep’s Clothing (KOR)
2023-04-05 • NSHC •
ThreatRecon observed SectorA phishing activity against South Korean targets increase sharply in 2022, with SectorA05 responsible for most observed cases and SectorA02 also active. The campaigns targeted researchers, government personnel, education, NGOs, broadcasting/telecom, finance, and individual investors, especially people connected to North Korea research and South Korean institutions. Operators impersonated trusted Korean services and organizations, including Naver electronic documents, Daum customer support, card verification notices, universities, public agencies, and financial brands, to harvest portal credentials or deliver lure documents. The report highlights phishing infrastructure using lookalike domains and overseas hosting, including a SupremeBytes-hosted sender IP and domains spoofing Naver, Google, Daum, Kakao, public agencies, universities, and banks.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | myartsonline.com | 2020-09-30 | 2024-09-05 |
| DOMAIN | eu5.net | 2023-04-05 | 2023-04-18 |
| DOMAIN | eu3.org | 2023-04-05 | 2023-04-18 |
| DOMAIN | daum-privacy.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | googlmeil.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | infinityfreeapp.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | kakaocop.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | eu3.biz | 2023-04-05 | 2023-04-18 |
| DOMAIN | dankook.onedviver.epizy.com | 2023-04-05 | 2023-04-18 |
| DOMAIN | glitch.me | 2023-04-05 | 2023-04-18 |
| DOMAIN | fleek.co | 2023-04-05 | 2023-04-18 |
| DOMAIN | nid.daurn.in.net | 2023-04-05 | 2023-04-18 |
| DOMAIN | kisa.42web.io | 2023-04-05 | 2023-04-18 |
| DOMAIN | daurn.in.net | 2023-04-05 | 2023-04-18 |
| IPv4 | 162.216.224.39 | 2023-04-05 | 2023-04-18 |
| DOMAIN | accounts.qocple.epizy.com | 2022-10-26 | 2023-04-18 |
| DOMAIN | 42web.io | 2022-08-25 | 2023-04-18 |
| DOMAIN | naver.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | kakao.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | snu.cloudfiles.epizy.com | 2022-06-15 | 2023-04-18 |
| DOMAIN | epizy.com | 2020-09-04 | 2023-04-18 |