Suspected DPRK Phishing Campaign Targets Naver; Separate Apple Domain Spoofing Cluster Identified

2024-10-29 Hunt.io

https://hunt.io/blog/dprk-phishing-targets-naver-apple-domain-spoofing

Thumbnail for Suspected DPRK Phishing Campaign Targets Naver; Separate Apple Domain Spoofing Cluster Identified

Hunt identified a suspected North Korean-linked phishing server targeting Naver users from an exposed directory at 158.247.238[.]155/naver on infrastructure hosted in Seoul. The server redirected port 80 traffic to the legitimate Naver site, hosted more than 200 domains, and contained folders and files for credential-theft pages, IP logging, and user tracking. The recon.htm page copied a Naver password-change flow with Korean text urging identity verification to block suspicious devices, while a related rtnurl file pointed to visitnhisserver[.]store and a redirect chain involving nextonlinecom[.]store. Hunt treats the attribution as tentative, noting that the Naver targeting, exposed phishing server, low-cost .store domains, and Let’s Encrypt certificates resemble activity often associated with Kimsuky, Lazarus, and other DPRK-linked operators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 35a101941f438a7d072b31eb3b666e2… 2024-10-29 2024-10-29
HASH 3201fa0f5d8269e556aec50f820f17e… 2024-10-29 2024-10-29
URL https://visitnhisserver.store/s… 2024-10-29 2024-10-29
URL https://nextonlinecom.store/ 2024-10-29 2024-10-29
DOMAIN vinetro.info 2024-10-29 2024-10-29
DOMAIN shelby-cp-ecole.org 2024-10-29 2024-10-29
DOMAIN schulen-horw.com 2024-10-29 2024-10-29
DOMAIN applelplus1.hydadhybidad2.xyz 2024-10-29 2024-10-29
DOMAIN westwindmotorinn.xyz 2024-10-29 2024-10-29
DOMAIN file-explorer-aerocenter.org 2024-10-29 2024-10-29
DOMAIN appleplus1.hydadhybidad2.xyz 2024-10-29 2024-10-29
DOMAIN ns3.dnsowl.com 2024-10-29 2024-10-29
DOMAIN nextonlinecom.store 2024-10-29 2024-10-29
DOMAIN visitnhisserver.store 2024-10-29 2024-10-29
DOMAIN domain-www.fnsc-law.info 2024-10-29 2024-10-29
IPv4 185.239.0.39 2024-10-29 2024-10-29
IPv4 84.32.186.252 2024-10-29 2024-10-29
IPv4 192.121.17.63 2024-10-29 2024-10-29
IPv4 206.206.125.237 2024-10-29 2024-10-29
IPv4 185.239.0.43 2024-10-29 2024-10-29
IPv4 185.239.2.170 2024-10-29 2024-10-29
IPv4 159.253.4.64 2024-10-29 2024-10-29
IPv4 158.247.238.155 2024-10-29 2024-10-29
IPv4 107.189.16.65 2024-10-29 2024-10-29
IPv4 185.239.0.42 2024-10-29 2024-10-29
IPv4 159.253.4.70 2024-10-29 2024-10-29

Related Reports

« Back