Preliminary File List Analysis of Kimsuky / APT43 Leak

2025-09-26 Siddhant

https://medium.com/@siddhantalokmishra/preliminary-file-list-analysis-of-kimsuky-apt43-leak-77b863e40c52

Thumbnail for Preliminary File List Analysis of Kimsuky / APT43 Leak

The analysis reviews file listings, shell history, browser history and development artifacts from the Phrack “APT Down — The North Korea Files” leak and frames them as Kimsuky/APT43-related material. The evidence shows malware-development and intrusion tooling activity, including API hashing, DLL loaders, reverse shells, C2 and tunneling repositories, TLS proxying, SOCKS5 work, Safe Browsing checks and eBPF/Rust components under a project called KoviD. The actor environment contained extensive South Korean GPKI source and binaries, Korean OCR processing of security documents, and reconnaissance against mail and network infrastructure, suggesting interest in Korean government and security systems. The report matters because it turns leaked operational artifacts into defensive context on likely tooling, target interests, development practices and possible phishing or covert-communication preparation.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN conf.leoaura.com 2025-09-26 2025-09-26
DOMAIN exchange.fcis.ned.org 2025-09-26 2025-09-26
DOMAIN swi-nwv2.ad.plc.ned.org 2025-09-26 2025-09-26
IPv4 163.29.149.131 2025-09-26 2025-09-26
IPv4 211.23.123.246 2025-09-26 2025-09-26
IPv4 210.71.195.10 2025-09-26 2025-09-26
IPv4 13.224.163.100 2025-09-26 2025-09-26
DOMAIN tw.systexcloud.com 2025-09-05 2025-09-26
IPv4 59.125.159.81 2025-09-05 2025-09-26
IPv4 118.163.30.45 2025-09-05 2025-09-26
IPv4 163.29.3.119 2025-09-05 2025-09-26

Related Actors

Related Reports

« Back