Ten Operators, Nine Campaigns, and a Backend With No Password: How a Single Vercel URL Exposed a Two-Year Korean Phishing Syndicate

2026-04-05 Break Glass Intelligence

https://intel.breakglass.tech/post/team24-ten-operators-vercel-phishing-syndicate-open-backend-korean-targeting

Thumbnail for Ten Operators, Nine Campaigns, and a Backend With No Password: How a Single Vercel URL Exposed a Two-Year Korean Phishing Syndicate

Breakglass Intelligence found an exposed phishing backend at arnptec[.]com after investigating a Vercel-hosted Naver credential-harvesting page, curly-spoon-sigma[.]vercel[.]app. Directory listing revealed ten operator directories, nine campaign themes, reusable kit templates, and a credential exfiltration endpoint under /team24/nvvvr/mab/send.php. The campaigns target South Korean services including Naver, Daum/Kakao, Cafe24, eCount, Korean webmail, corporate accounts, WeTransfer, and domain-registration services. The Naver kit uses a double-tap password collection flow, while timestamps and multiple disabled Vercel projects indicate at least two years of activity and repeated free-tier hosting abuse. The report notes the Korean targeting pattern aligns with Kimsuky/APT43 behavior but also cautions that the activity could be a financially motivated Korean-language phishing syndicate.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN arnptec.com 2026-04-05 2026-04-05

Related Actors

Related Reports

2026-04-17 • 90% Match
#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
Shares tags: Kimsuky, Phishing • Same author: Break Glass Intelligence • Published within a month
« Back