Preliminary File List Analysis of Kimsuky / APT43 Leak
2025-09-26 • Siddhant •
The analysis reviews file listings, shell history, browser history and development artifacts from the Phrack “APT Down — The North Korea Files” leak and frames them as Kimsuky/APT43-related material. The evidence shows malware-development and intrusion tooling activity, including API hashing, DLL loaders, reverse shells, C2 and tunneling repositories, TLS proxying, SOCKS5 work, Safe Browsing checks and eBPF/Rust components under a project called KoviD. The actor environment contained extensive South Korean GPKI source and binaries, Korean OCR processing of security documents, and reconnaissance against mail and network infrastructure, suggesting interest in Korean government and security systems. The report matters because it turns leaked operational artifacts into defensive context on likely tooling, target interests, development practices and possible phishing or covert-communication preparation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | conf.leoaura.com | 2025-09-26 | 2025-09-26 |
| DOMAIN | exchange.fcis.ned.org | 2025-09-26 | 2025-09-26 |
| DOMAIN | swi-nwv2.ad.plc.ned.org | 2025-09-26 | 2025-09-26 |
| IPv4 | 163.29.149.131 | 2025-09-26 | 2025-09-26 |
| IPv4 | 211.23.123.246 | 2025-09-26 | 2025-09-26 |
| IPv4 | 210.71.195.10 | 2025-09-26 | 2025-09-26 |
| IPv4 | 13.224.163.100 | 2025-09-26 | 2025-09-26 |
| DOMAIN | tw.systexcloud.com | 2025-09-05 | 2025-09-26 |
| IPv4 | 59.125.159.81 | 2025-09-05 | 2025-09-26 |
| IPv4 | 118.163.30.45 | 2025-09-05 | 2025-09-26 |
| IPv4 | 163.29.3.119 | 2025-09-05 | 2025-09-26 |