https://www.bleepingcomputer.com/news/security/north-korean-kimsuky-hackers-exposed-in-alleged-data-breach/
The North Korean state-sponsored hackers known as Kimsuky has reportedly suffered a data breach after two hackers, who describe themselves as the opposite of Kimsuky’s values, stole the group’s data and leaked it publicly online. … The 8.9GB dump currently hosted on the ‘Distributed Denial of Secrets’' website contains, among others:
- Phishing logs with multiple dcc.mil.kr (Defense Counterintelligence Command) email accounts.
- Other targeted domains: spo.go.kr, korea.kr, daum.net, kakao.com, naver.com.
- .7z archive containing the complete source code of South Korea’s Ministry of Foreign Affairs email platform (“Kebi”), including webmail, admin, and archive modules.
- References to South Korean citizen certificates and curated lists of university professors.
- PHP “Generator” toolkit for building phishing sites with detection evasion and redirection tricks.
- Live phishing kits.
- Unknown binary archives (voS9AyMZ.tar.gz, Black.x64.tar.gz) and executables (payload.bin, payload_test.bin, s.x64.bin) not flagged in VirusTotal.
- Cobalt Strike loaders, reverse shells, and Onnara proxy modules found in VMware drag-and-drop cache.
- Chrome history and configs linking to suspicious GitHub accounts (wwh1004.github.io, etc.), VPN purchases (PureVPN, ZoogVPN) via Google Pay, and frequent use of hacking forums (freebuf.com, xaker.ru).
- Google Translate use for Chinese error messages and visits to Taiwan government and military sites.
- Bash history with SSH connections to internal systems. …
Regards