Larva-25010 - APT Down 공격자 PC 분석

2025-10-02 Ahnlab Larva-25010 - Analysis of the APT Down attacker PC

https://asec.ahnlab.com/ko/90408/

Thumbnail for Larva-25010 - APT Down 공격자 PC 분석

AhnLab reviewed public data from “APT Down: the North Korea Files” and related disclosures about an attacker workstation that the original authors claimed belonged to a Kimsuky member. The material describes sustained intrusions against South Korean administrative agencies, military organizations, and telecommunications targets, with additional reconnaissance activity aimed at Taiwan and Japan. The excerpt links the activity to credential and certificate exposure, possible shared government passwords, phishing preparation for Naver and Kakao login pages, and tools or techniques including Ivanti exploitation, syslogk, Tinyshell, phishing, and Cobalt Strike. Listed indicators include multiple file hashes, the domain websecuritynotices[.]com, and IP address 104[.]167[.]16[.]97, making the report useful for defenders tracking exposed infrastructure and intrusion artifacts tied to the APT Down dataset.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 2a5a29309d0957d46b7d59faa7aaa2e… 2025-10-02 2025-10-02
HASH 8c939345536c4de27642ef6604794e8… 2025-10-02 2025-10-02
HASH 6efde7c43d60cdbedf6da46c0649f63… 2025-10-02 2025-10-02
HASH 2c0fbdb97439e079bbd8919c39598508 2025-10-02 2025-10-02
HASH 64433d2275516b0bb6919a49bf41587… 2025-10-02 2025-10-02
IPv4 104.167.16.97 2025-10-02 2025-10-02
DOMAIN websecuritynotices.com 2025-08-22 2025-10-02

Related Actors

Related Reports

« Back