âMillion OK!!!!â and the Naver Facade: Tracking Recent Suspected Kimsuky Infrastructure
ID: 27626532-7322-5389-8fd0-34cdeb12bb27
STIX ID: report--27626532-7322-5389-8fd0-34cdeb12bb27
Feed Name: Hunt.io Blog
Threat Score
Hunt researchers observed a cluster of IPs and recently registered domains returning a unique 'Million OK !!!!' HTTP response and using Naver branding, attributing the infrastructure to North Korean APT Kimsuky; the report catalogs IPs, resolving domains, Sectigo TLS certificates, certificate fingerprints, and a registrant email previously tied to KLogEXE/FPSpy, providing actionable IOCs and TTPs for monitoring and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
