Kimsuky Group: Track the King of the Spear-Phishing

2019-10-04 FSI

https://www.virusbulletin.com/uploads/pdf/conference_slides/2019/VB2019-Kim.pdf

Attachments

VB2019-Kim.pdf (26 MB)

Thumbnail for Kimsuky Group: Track the King of the Spear-Phishing

The Financial Security Institute presentation tracks Kimsuky as a North Korea-linked spear-phishing actor active since at least 2013 and still operating in 2019, targeting infrastructure, government, North Korean defectors, politicians, diplomatic and human-rights organizations for intelligence collection and social disruption. It catalogs the group’s server-side phishing toolchain—mailer components, beacons, phishing pages and loggers—alongside malicious HWP and camouflaged documents, scripts, downloaders and info-stealers used to deliver payloads and harvest accounts or host information. Case studies show defenders using the actor’s OPSEC failures, including directory listing, leaked FTP credentials and file-download vulnerabilities, to discover malware, mailer infrastructure and C2 relationships such as suppcrt-seourity[.]esy.es, member-authorize[.]com, ddlovke[.]kr and military[.]co.kr. The slides emphasize proactive tracking and cooperation with relevant agencies because monitoring attacker infrastructure exposed new malware, server-side toolkits and links between compromised Korean sites and hosting services.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN member-authorize.com 2019-10-04 2020-11-12
IPv4 185.224.138.29 2019-03-04 2020-11-12
HASH 53ac231e8091abcd0978124f9268b4e4 2019-10-04 2019-10-04
HASH 8b59ea1ee28e0123da82801abc0cce4d 2019-10-04 2019-10-04
DOMAIN ddlove.kr 2019-10-04 2019-10-04
DOMAIN ddlovke.kr 2019-10-04 2019-10-04
DOMAIN military.co.kr 2019-10-04 2019-10-04
IPv4 211.202.2.51 2019-10-04 2019-10-04
HASH f22db1e3ea74af791e34ad5aa0297664 2019-03-04 2019-10-04
HASH 4de21c3af64b3b605446278de92dfff4 2019-03-04 2019-10-04
DOMAIN gyjmc.com 2019-01-30 2019-10-04

Related Actors

Related Reports

« Back