Suspected DPRK Phishing Campaign Targets Naver; Separate Apple Domain Spoofing Cluster Identified
2024-10-29 • Hunt.io •
https://hunt.io/blog/dprk-phishing-targets-naver-apple-domain-spoofing
Hunt identified a suspected North Korean-linked phishing server targeting Naver users from an exposed directory at 158.247.238[.]155/naver on infrastructure hosted in Seoul. The server redirected port 80 traffic to the legitimate Naver site, hosted more than 200 domains, and contained folders and files for credential-theft pages, IP logging, and user tracking. The recon.htm page copied a Naver password-change flow with Korean text urging identity verification to block suspicious devices, while a related rtnurl file pointed to visitnhisserver[.]store and a redirect chain involving nextonlinecom[.]store. Hunt treats the attribution as tentative, noting that the Naver targeting, exposed phishing server, low-cost .store domains, and Let’s Encrypt certificates resemble activity often associated with Kimsuky, Lazarus, and other DPRK-linked operators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 35a101941f438a7d072b31eb3b666e2… | 2024-10-29 | 2024-10-29 |
| HASH | 3201fa0f5d8269e556aec50f820f17e… | 2024-10-29 | 2024-10-29 |
| URL | https://visitnhisserver.store/s… | 2024-10-29 | 2024-10-29 |
| URL | https://nextonlinecom.store/ | 2024-10-29 | 2024-10-29 |
| DOMAIN | vinetro.info | 2024-10-29 | 2024-10-29 |
| DOMAIN | shelby-cp-ecole.org | 2024-10-29 | 2024-10-29 |
| DOMAIN | schulen-horw.com | 2024-10-29 | 2024-10-29 |
| DOMAIN | applelplus1.hydadhybidad2.xyz | 2024-10-29 | 2024-10-29 |
| DOMAIN | westwindmotorinn.xyz | 2024-10-29 | 2024-10-29 |
| DOMAIN | file-explorer-aerocenter.org | 2024-10-29 | 2024-10-29 |
| DOMAIN | appleplus1.hydadhybidad2.xyz | 2024-10-29 | 2024-10-29 |
| DOMAIN | ns3.dnsowl.com | 2024-10-29 | 2024-10-29 |
| DOMAIN | nextonlinecom.store | 2024-10-29 | 2024-10-29 |
| DOMAIN | visitnhisserver.store | 2024-10-29 | 2024-10-29 |
| DOMAIN | domain-www.fnsc-law.info | 2024-10-29 | 2024-10-29 |
| IPv4 | 185.239.0.39 | 2024-10-29 | 2024-10-29 |
| IPv4 | 84.32.186.252 | 2024-10-29 | 2024-10-29 |
| IPv4 | 192.121.17.63 | 2024-10-29 | 2024-10-29 |
| IPv4 | 206.206.125.237 | 2024-10-29 | 2024-10-29 |
| IPv4 | 185.239.0.43 | 2024-10-29 | 2024-10-29 |
| IPv4 | 185.239.2.170 | 2024-10-29 | 2024-10-29 |
| IPv4 | 159.253.4.64 | 2024-10-29 | 2024-10-29 |
| IPv4 | 158.247.238.155 | 2024-10-29 | 2024-10-29 |
| IPv4 | 107.189.16.65 | 2024-10-29 | 2024-10-29 |
| IPv4 | 185.239.0.42 | 2024-10-29 | 2024-10-29 |
| IPv4 | 159.253.4.70 | 2024-10-29 | 2024-10-29 |