Kimsuky APT Domains and URLs from Maltrail Feed
This brief summarizes newly published IOCs consisting of domains and URLs associated with the Kimsuky APT group as of June 2nd, 2026, sourced from a Maltrail feed.
This threat brief summarizes indicators of compromise (IOCs) associated with the Kimsuky APT group, a North Korean threat actor known for cyber espionage and intelligence gathering. The IOCs, consisting of domains and a URL, were extracted from a Maltrail feed published on June 2nd, 2026. These indicators can be used to identify and block malicious network traffic related to Kimsuky’s activities. Kimsuky is known to target South Korean government entities, think tanks, and individuals involved in foreign policy and national security. The group employs a variety of techniques, including spear-phishing, watering hole attacks, and the use of custom malware. These IOCs are likely associated with command-and-control infrastructure or phishing campaigns.
Attack Chain
While this report focuses primarily on IOCs, a typical Kimsuky attack chain might involve the following steps:
- Spear-phishing: Kimsuky initiates contact via highly targeted spear-phishing emails, often masquerading as legitimate correspondence from trusted sources.
- Malicious Attachment/Link: The emails contain malicious attachments (e.g., weaponized documents) or links that lead to compromised websites.
- Initial Access: Upon opening the attachment or clicking the link, malware is executed on the victim’s machine.
- Persistence: The malware establishes persistence through various methods, such as scheduled tasks or registry modifications, to ensure continued access to the system.
- Command and Control: The malware connects to command-and-control (C2) servers to receive instructions and exfiltrate data. This is where the IOCs in this brief become relevant as potential C2 destinations.
- Lateral Movement: The attackers attempt to move laterally within the network, compromising additional systems and accounts.
- Data Exfiltration: Sensitive data is collected and exfiltrated to the attacker’s servers.
- Espionage: The ultimate goal of Kimsuky is often espionage, gathering intelligence on South Korean government policies, defense strategies, and diplomatic relations.
Impact
Compromise by Kimsuky can result in the loss of sensitive information, including government secrets, personal data, and intellectual property. This can have significant national security and economic consequences for targeted organizations. Successful attacks can also damage the reputation of affected entities and erode public trust. Given Kimsuky’s focus on espionage, the primary impact is long-term strategic disadvantage for targeted nations.
Recommendation
- Ingest the domain IOCs listed in the
iocssection into your SIEM or threat intelligence platform for alerting and blocking. - Monitor network traffic for connections to the domains and URL listed in the
iocssection, specifically looking for suspicious outbound connections. - Deploy the Sigma rule provided below to detect DNS queries to Kimsuky infrastructure.
- Investigate any systems that have communicated with the IOCs from this report, prioritizing systems belonging to users involved in South Korean foreign policy, national security, or defense.
Detection coverage 2
Detect DNS Queries to Kimsuky Domains
mediumDetects DNS queries to domains associated with the Kimsuky APT group.
Detect Outbound Connection to Kimsuky Domains
mediumDetects outbound network connections to domains associated with the Kimsuky APT group.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
49
domain
1
url
| Type | Value |
|---|---|
| url | https://api.github.com/repos/stamparm/maltrail/commits/f04e78fc9e109400f740b2e34c86ad5630c7048a |
| domain | 0jr87375qt.v6.navy |
| domain | 2ecy51395u.v6.navy |
| domain | b8fq9189g6.dns.navy |
| domain | confirm1.moois-nid.remotewire.net |
| domain | cxmfcubfnq.dns.navy |
| domain | diaxwn61lp.dynv6.net |
| domain | dns-setup.remotewire.net |
| domain | e639kk.wjyx49u3cu3.dns.army |
| domain | egbzqa25gw.v6.navy |
| domain | health-doc.giize.com |
| domain | info.dns-setup.remotewire.net |
| domain | ip-cloud.theworkpc.com |
| domain | ips-doc.webredirect.org |
| domain | ips.dynuddns.net |
| domain | ispd.nts-write.remotewire.net |
| domain | jbyaa6xotk.v6.army |
| domain | lopm.webredirect.org |
| domain | mois-doc.roxa.org |
| domain | mois.mytunnel.org |
| domain | moois-nid.remotewire.net |
| domain | ms-cloud.ezgateway.net |
| domain | mybox.camdvr.org |
| domain | n-corp.hets12ex.dns.army |
| domain | n2gdnw08p4.dns.navy |
| domain | nav-log.moois-nid.remotewire.net |
| domain | naver.mywire.org |
| domain | ncodcnpass.dns.navy |
| domain | nd8f3lxih4.v6.navy |
| domain | ndoc.nid-sign.opik.net |
| domain | nid-nver.mybox.camdvr.org |
| domain | nid-sign.opik.net |
| domain | nid.ips-doc.webredirect.org |
| domain | nid.naver.mywire.org |
| domain | nid.ncodcnpass.dns.navy |
| domain | nid.nid-sign.opik.net |
| domain | nid.niws.mysynology.net |
| domain | nid.puoios.o-r.kr |
| domain | niws.mysynology.net |
| domain | nj1oayuy2o.dns.army |
| domain | nps-load.remotewire.net |
| domain | nst.mysynology.net |
| domain | nts-write.remotewire.net |
| domain | nudoc-check.e639kk.wjyx49u3cu3.dns.army |
| domain | nusrauth.gleeze.com |
| domain | passnid.lopm.webredirect.org |
| domain | puoios.o-r.kr |
| domain | r461wn14u1.dns.army |
| domain | support.nst.mysynology.net |
| domain | tahpuoto94.dns.army |