Like many other “““hackers”””, I’ve always had a bit of a fascination for APTs. If you have never heard the term APT, it means “Advanced Persistent Threat”. They are computer engineers, often affiliated to governments, focused on pursuing military objectives like intelligence collection, sabotage, etc.
Recently, one of them got popped, very publicly. The last time, I think, we’ve seen something of the sort (though it was more significant) was the shadowbrokersss leak/hack. It lead to devastating attacks that impacted multiple countries’ critical infrastructure.
We will see that, in this case, the APT stands more for Advanced Persistent Trash than anything.
I don’t claim that you will find unforseen new discoveries here. More clever people than me have probably looked at it before. These are just notes & observations.
It is also not exhaustive, I have just briefly been looking at it for now. I plan on making this a multi-part series, and dive deeper in some subjects. For now, we’re just skimming through everything.
Some notes on the article
Infamously, the KIMSUKY group is affialated to North Korea. Until now, this was the main allegation anyway. However, this article seem to claim that the user was Chinese-speaking. I am not going to go into the implications of such allegations, but this was one of the most interesting details to me.
Because the authors of the article are very nice, they provided a dump of the computer they got access to. It is not explained how they got access to this machine, but what I suspect is that they found Remote Access credentials in a malware sample and a corresponding IP address, and simply got in. That is the most simple explanation, although that would imply the operator is very sloppy. I’m inclined to believe they are indeed quite sloppy.
Alright, let’s download the dump, open a beer, and go through it, shall we ?
Briefly exploring the dump
The dump is split in 3 directories:
Files and lists
Firstly, we can see a screenshot of the environnement of the user:

We can see references to what seems like open source projects. However, we don’t know if this screenshot comes from the malware writer (named Kim by the bloggers), or by our leakers themselves. There isn’t any interesting metadata on it.
A much more interesting file is the Chrome history, which indicates the user’s navigation history. This 82MB file (damn…) retraces all the researches done from this session by the threat actor Kim.
At a glance, we can see the user has visited Taiwanese websites, Baidu, Stackoverflow, and even Google (google.com.hk). I also found references to Yandex, the russian search engine.
References to an Open-source Linux rootkit were also found. Some projects, like this one were even added to the toolbar.

We can see Kim is trying to have malware for both Windows & Linux, with a focus in trying to keep a backdoor. Honestly, there are many MANY projects saved, with a varying degree of quality. Some are very popular (like the Havoc framework), some are unfinished. There is honestly a bit of everything, but it seems this developer likes to take……inspiration from open-source projects.
A weird detail that I found was that this user seem to visit a few times a fork of the Havoc Framework.
Here is the url if you are interested: https://github.com/killvxk/Havoc-HavocFramework
At the time of writing, this GitHub user has been collecting in repositories projects and PoCs daily. It doesn’t mean this user is KIMSUKY but it is weird that this repository has been visited. Currently, this fork has zero stars.

it’s worth noting for the future that this killvxk dude signs his commit with this GPG key:
B5690EEEBB952194, which is also mentionned in the setup-go repo ?this feels a bit weird, but it could be nothing. // TODO investigate this later
Of course, as mentionned in the article, I also found references to South Korean websites (mostly governmental, but also GCloud instances). We also find references to military taiwanese email domains, most likely accessed through compromised accounts:

We also find a few IP addresses:
- 114.156.22.212 (Japanese IP with a VPN deployed)
- 88.99.191.198 (German IP, Linux deployed with SSH open)
- 163.29.3.119 (taiwanese IP, nothing shows up on Censys)
- 211.23.123.246 (taiwanese IP, nothing shows up on Censys)
- 222.112.8.34 (Korean IP with Fortinet + web server deployed)
It’s possible these IPs have been used as phishing or C2 servers in the past (or still are). It would be helpful to find more, but the file is to big and it’s difficult to go through this by hand. At the end of this investigation, I will probably use an XML parser to go through the file, and recover interesting information.
vps directory
This directory contains the configuration of the VPS mentionned in the article.
We do find a shadow file with the following hash for root:
root:$6$AwGRCH4mtgeOOosQ$0n3q27yEoMJ/04hJjazEue5oTSstXtKfvvDGlrN0OlD5wWPYe6S/6hnaz/S94YPUFKSlw1edzFHRysGKnZ9zB1:20251:0:99999:7:::
There are also a bunch of SSH keys, and ssh config (PermitRootLogin is configured to true, lol)
ssh keys
For OSINT purposes, let’s keep the keys here:
A DSA Public / Private key pair:
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABsQAAAAdzc2gtZH
NzAAAAgQCdm9CabRiAF+lPSTmRHunBoZM6Af0Z6eIaU2oDpATaxI8BTul1GQ/HM3sQ0WBO
x9BfukPGBquBwm8dZCOF2pe0d6jaK5saruHDnUspa8Bad4GDjE6XOUJQdYqBGihxzvGbjz
gA1aHbeYudc6d3+MlHn3XV/PCF3KEyFlWUUmHmpwAAABUA61LR7MxAH+OacFOEhpiZ9uX1
d/8AAACAWJPxcLFuNHgo6LNDc9Kdp1NuZ3SytR+yGsBdHXG98YvtF6Vzx9jQBAtl60chHd
3gtBKmPigwVjlDWK4Okw5RFWEYVpZxP7XUqag6tgbnGlw8hiyMylYlLBymLaxDOq3tqq4R
UDMda70YKRta9BivcNDFdWgfTFtGGUR9Ct9btGcAAACAAuLze+Cu7CsFMYvkrCteiOmtS6
azEgz98iHqhTBK8u0nb6NPAUWv8dGXlh4kFhxgmhM3FcCw005KU9oIsdoBEiJqRA9g7SVE
1HCtaKkqNxBhTX8MVyBeu61zUZZYvOn+qxSpe3jSCWdUmegc8pugCZ5WHkCXz6FltADgwR
Fg+poAAAHotDUpp7Q1KacAAAAHc3NoLWRzcwAAAIEAnZvQmm0YgBfpT0k5kR7pwaGTOgH9
GeniGlNqA6QE2sSPAU7pdRkPxzN7ENFgTsfQX7pDxgargcJvHWQjhdqXtHeo2iubGq7hw5
1LKWvAWneBg4xOlzlCUHWKgRoocc7xm484ANWh23mLnXOnd/jJR5911fzwhdyhMhZVlFJh
5qcAAAAVAOtS0ezMQB/jmnBThIaYmfbl9Xf/AAAAgFiT8XCxbjR4KOizQ3PSnadTbmd0sr
UfshrAXR1xvfGL7Relc8fY0AQLZetHIR3d4LQSpj4oMFY5Q1iuDpMOURVhGFaWcT+11Kmo
OrYG5xpcPIYsjMpWJSwcpi2sQzqt7aquEVAzHWu9GCkbWvQYr3DQxXVoH0xbRhlEfQrfW7
RnAAAAgALi83vgruwrBTGL5KwrXojprUumsxIM/fIh6oUwSvLtJ2+jTwFFr/HRl5YeJBYc
YJoTNxXAsNNOSlPaCLHaARIiakQPYO0lRNRwrWipKjcQYU1/DFcgXrutc1GWWLzp/qsUqX
t40glnVJnoHPKboAmeVh5Al8+hZbQA4MERYPqaAAAAFQC2vvVreGmHpt5syXkubsSFP9it
nAAAABByb290QHNnMjQudnBzLmJ6AQI=
-----END OPENSSH PRIVATE KEY-----
ssh-dss AAAAB3NzaC1kc3MAAACBAJ2b0JptGIAX6U9JOZEe6cGhkzoB/Rnp4hpTagOkBNrEjwFO6XUZD8czexDRYE7H0F+6Q8YGq4HCbx1kI4Xal7R3qNormxqu4cOdSylrwFp3gYOMTpc5QlB1ioEaKHHO8ZuPOADVodt5i51zp3f4yUefddX88IXcoTIWVZRSYeanAAAAFQDrUtHszEAf45pwU4SGmJn25fV3/wAAAIBYk/FwsW40eCjos0Nz0p2nU25ndLK1H7IawF0dcb3xi+0XpXPH2NAEC2XrRyEd3eC0EqY+KDBWOUNYrg6TDlEVYRhWlnE/tdSpqDq2BucaXDyGLIzKViUsHKYtrEM6re2qrhFQMx1rvRgpG1r0GK9w0MV1aB9MW0YZRH0K31u0ZwAAAIAC4vN74K7sKwUxi+SsK16I6a1LprMSDP3yIeqFMEry7Sdvo08BRa/x0ZeWHiQWHGCaEzcVwLDTTkpT2gix2gESImpED2DtJUTUcK1oqSo3EGFNfwxXIF67rXNRlli86f6rFKl7eNIJZ1SZ6Bzym6AJnlYeQJfPoWW0AODBEWD6mg== [email protected]
A RSA Public / Private key pair:
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAABlwAAAAdzc2gtcn
NhAAAAAwEAAQAAAYEA5IVSkm4WEJo2ipV/SK0AGN6Ep7RjkgbuACSQ0pEtPaflYA25SxwB
fgJ2cE1GdPwbc2A+DaRpvbCDgWw5lZzFSpnondYTKX+O4cwyyPLRKFCC8v5lkSu7bwop1B
fBnpdG3/kbFDEmd0p00rqZYlx2t9YabwxOg0mwK5pFBJcNrcey6qbeu0GXQnZsBpHwe4OU
oh6q9NNLWNiGpcEdT6tVCWzjF/ilvv/8g73yHzUTM2txn678YlX//rr9X5aGiejJyfjszg
kfemG8D+sxORUqcEgE4RfB0WF+iksGhyMlqQTEY9YRbd5xG31M6mxAYJ3S3KxNNclo/Yj9
BP9gT4Ot9EloK2ZEm4a1D22dFKlqSpAYCfMAFgql4Vcmo7KzC4Nxsg07pHXZxrt6Pe6hP1
zLNdVRiLHaJ4bF84hNR3Ez+bsusBpre5/Ld7gqmJ1WYwntRfRFSKtDONibKBDRnRyWHecH
gnBb7zcowXOUVwUdnBllaM1r8zoFeUTLr50H1BRvAAAFiL8qY9a/KmPWAAAAB3NzaC1yc2
EAAAGBAOSFUpJuFhCaNoqVf0itABjehKe0Y5IG7gAkkNKRLT2n5WANuUscAX4CdnBNRnT8
G3NgPg2kab2wg4FsOZWcxUqZ6J3WEyl/juHMMsjy0ShQgvL+ZZEru28KKdQXwZ6XRt/5Gx
QxJndKdNK6mWJcdrfWGm8MToNJsCuaRQSXDa3Hsuqm3rtBl0J2bAaR8HuDlKIeqvTTS1jY
hqXBHU+rVQls4xf4pb7//IO98h81EzNrcZ+u/GJV//66/V+Whonoycn47M4JH3phvA/rMT
kVKnBIBOEXwdFhfopLBocjJakExGPWEW3ecRt9TOpsQGCd0tysTTXJaP2I/QT/YE+DrfRJ
aCtmRJuGtQ9tnRSpakqQGAnzABYKpeFXJqOyswuDcbINO6R12ca7ej3uoT9cyzXVUYix2i
eGxfOITUdxM/m7LrAaa3ufy3e4KpidVmMJ7UX0RUirQzjYmygQ0Z0clh3nB4JwW+83KMFz
lFcFHZwZZWjNa/M6BXlEy6+dB9QUbwAAAAMBAAEAAAGAO6diCr+aGvNm0X59H6epotRTpM
O+SlxsvLTO6WjkenfdtNlgSW8iJJbX/DDv95HoSJITINSOleoCKkLqNVgbWIIc6zb7AZY+
4kq/5x0b5H4/8NbgBKl54F6y1J7u+EtdQRJyMy8xb2qMXIZBjB+/DfZiKCL6S+NsjbVT1w
LnmznKRt8Qvak9pyfqwzxNnrCWmEuRLSALR0IexB5JXIbJSBCYp6VM/zMr4+gt0F+2h3HA
04KGd9UjYofFpLJSpKWTqVDkmcHTJja6TppLvi8BSnYEJdR3c9VSLSTtHEdilF/z+Oqckb
FAZ5rH+SNfkS5lB3y6gAuzTW0PCFk+EOTa8gY7flYcdPdwQ0okoqoSNf+m+7NfmQfNACYe
0PDxZuywNqWsEQDH3n4SomV4B2MtnwsSBu82WzmO9W/B/XCrsXgMMlaKEZLmsB/r1s54/6
KN+9MzcCqZlW12jkWSgiCU3hdWgm2paNOnVO1KUIc929SWudriG4O8W0b7xxiNdoshAAAA
wQDbG9ed2vH1gAXevjsqhph6VFdcQ5kmVjHzeaLX1Ty5z/8Kr3dBoNfHks9O0I7dtgcpIx
nKbaU6NKQYIBsQmZjKdhDPbQIO9cKe2ALGeprMddPc6LlB+59C5SjFANt2qEj6gXooJPeR
PT/nf4iIjwk1i2yOx4FdoQSmi6FQgOJC2XorOD+7J7DEqySEfddVKnZHTTKNAvw8NxvrrP
mmQVL/5PEehCRS3jgvCPCxrN0WZFep3WZDtmcDcSd/TXkzd4kAAADBAPQdtVUhPDWibaDW
7YN4En43fwAqpwRvi7EV0XMbDKOpWWdS4ILuh19jS54p6ioj5RuhPEX3uR6U/J5xKoRNuq
PoSlCd3otM4U33vPbzjzcH5/3m2qzRW+LWT/+B2iTB+pG74aWtXSW1MnoetoxPjDdeP4ut
eIaBKlu2DGpzNXI45sZOI+ukyg+Y6YRe6b3GEGIcuF/qpFl4/gVhktkjcchCwVWg2VkWZX
ri980OF5kSj7cDRsQvlQI7ukX6CvLetQAAAMEA76VCNN/LNMw6Lth+etrP27BqpZnEbN2/
VhQxh11ogxMbmwegyED8N5g+49JltPsAwoNnp7h/bmuVxxj6U2WoRcR0CZDAZf/tz8onCD
3kpu1T+EKQmvjqG20pYAT/kdmZjYZnAOzdmuPoHAl2B3WO7VYS+dOFNM4mO3vzc+ghVTwL
yHpFpTbqndU2zZSPB9pfweLvFLcjJtrLtOiTGxNu7wwNw+HUAwxZkB4PbvJwVAim6UBMtk
kcBjfy2v9GonkTAAAAEHJvb3RAc2cyNC52cHMuYnoBAg==
-----END OPENSSH PRIVATE KEY-----
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDkhVKSbhYQmjaKlX9IrQAY3oSntGOSBu4AJJDSkS09p+VgDblLHAF+AnZwTUZ0/BtzYD4NpGm9sIOBbDmVnMVKmeid1hMpf47hzDLI8tEoUILy/mWRK7tvCinUF8Gel0bf+RsUMSZ3SnTSupliXHa31hpvDE6DSbArmkUElw2tx7Lqpt67QZdCdmwGkfB7g5SiHqr000tY2IalwR1Pq1UJbOMX+KW+//yDvfIfNRMza3GfrvxiVf/+uv1floaJ6MnJ+OzOCR96YbwP6zE5FSpwSAThF8HRYX6KSwaHIyWpBMRj1hFt3nEbfUzqbEBgndLcrE01yWj9iP0E/2BPg630SWgrZkSbhrUPbZ0UqWpKkBgJ8wAWCqXhVyajsrMLg3GyDTukddnGu3o97qE/XMs11VGIsdonhsXziE1HcTP5uy6wGmt7n8t3uCqYnVZjCe1F9EVIq0M42JsoENGdHJYd5weCcFvvNyjBc5RXBR2cGWVozWvzOgV5RMuvnQfUFG8= [email protected]
I’m guessing these were only used for this server, but we never know.
Apache
There is also an apache / letsencrypt configuration directory with references to these domains:
- sponetcloud.com (Registered with this email:
[email protected]- name: Edwin Dietrich ; SSL certificate created on May 13 2025) - websecuritynotices.com (Registered with this email:
[email protected]- name: Mortimer Little ; SSL certificate created on April 9 2025)
crontabs ?
This is the crontab file, it references files that I could not find:
# DO NOT EDIT THIS FILE - edit the master and reinstall.
# (- installed on Wed Jun 25 20:44:01 2025)
# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $)
@daily /var/tmp/.update-logs/./History >/dev/null 2>&1 & disown
@reboot /var/tmp/.update-logs/./Update >/dev/null 2>&1 & disown
* * * * * /var/tmp/.update-logs/./History >/dev/null 2>&1 & disown
@monthly /var/tmp/.update-logs/./Update >/dev/null 2>&1 & disown
* * * * * /var/tmp/.update-logs/./.b >/dev/null 2>&1 & disown
www phishing kit
In the www/ directory, we find a phishing kit written in PHP (ewww).
Looking at the config file, we can find a few interesting details:
- there is a blacklist of IP addresses, seemlingly owned by CTI companies,
- there is a whitelist of locales (US, Japanese, South Korean, but not Taiwanese ?)
- there is a path to a directory called
log/passwords*, with credentials inside. So many of them. I think the passwords have been removed, but you can still see the emails in the logs.
The kit works by maskerading as a Kakao (a chatting app, like WhatsApp or WeChat) login page.
/var/logs
There are so many, so many of them. I first looked at the auth.logs file, but could not find anything relevant.
It might be worth to look at the access logs, and syslogs but it is already getting late and I want to conclude this.
work directory
This is actually the most interesting of the three. There is a lot of source code, particularly of tools mentionned before. I think it deserves a second blog post, just for this one.
Stay tuned.
See you next time :)~