logo

“Million OK!!!!” and the Naver Facade: Tracking Recent Suspected Kimsuky Infrastructure

ID: 27626532-7322-5389-8fd0-34cdeb12bb27

STIX ID: report--27626532-7322-5389-8fd0-34cdeb12bb27

Feed Name: Hunt.io Blog

Threat Score
80/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Hunt researchers observed a cluster of IPs and recently registered domains returning a unique 'Million OK !!!!' HTTP response and using Naver branding, attributing the infrastructure to North Korean APT Kimsuky; the report catalogs IPs, resolving domains, Sectigo TLS certificates, certificate fingerprints, and a registrant email previously tied to KLogEXE/FPSpy, providing actionable IOCs and TTPs for monitoring and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.