Skip to content
Threat Feed
medium threat

Kimsuky APT Domains and URLs from Maltrail Feed

This brief summarizes newly published IOCs consisting of domains and URLs associated with the Kimsuky APT group as of June 2nd, 2026, sourced from a Maltrail feed.

This threat brief summarizes indicators of compromise (IOCs) associated with the Kimsuky APT group, a North Korean threat actor known for cyber espionage and intelligence gathering. The IOCs, consisting of domains and a URL, were extracted from a Maltrail feed published on June 2nd, 2026. These indicators can be used to identify and block malicious network traffic related to Kimsuky’s activities. Kimsuky is known to target South Korean government entities, think tanks, and individuals involved in foreign policy and national security. The group employs a variety of techniques, including spear-phishing, watering hole attacks, and the use of custom malware. These IOCs are likely associated with command-and-control infrastructure or phishing campaigns.

Attack Chain

While this report focuses primarily on IOCs, a typical Kimsuky attack chain might involve the following steps:

  1. Spear-phishing: Kimsuky initiates contact via highly targeted spear-phishing emails, often masquerading as legitimate correspondence from trusted sources.
  2. Malicious Attachment/Link: The emails contain malicious attachments (e.g., weaponized documents) or links that lead to compromised websites.
  3. Initial Access: Upon opening the attachment or clicking the link, malware is executed on the victim’s machine.
  4. Persistence: The malware establishes persistence through various methods, such as scheduled tasks or registry modifications, to ensure continued access to the system.
  5. Command and Control: The malware connects to command-and-control (C2) servers to receive instructions and exfiltrate data. This is where the IOCs in this brief become relevant as potential C2 destinations.
  6. Lateral Movement: The attackers attempt to move laterally within the network, compromising additional systems and accounts.
  7. Data Exfiltration: Sensitive data is collected and exfiltrated to the attacker’s servers.
  8. Espionage: The ultimate goal of Kimsuky is often espionage, gathering intelligence on South Korean government policies, defense strategies, and diplomatic relations.

Impact

Compromise by Kimsuky can result in the loss of sensitive information, including government secrets, personal data, and intellectual property. This can have significant national security and economic consequences for targeted organizations. Successful attacks can also damage the reputation of affected entities and erode public trust. Given Kimsuky’s focus on espionage, the primary impact is long-term strategic disadvantage for targeted nations.

Recommendation

  • Ingest the domain IOCs listed in the iocs section into your SIEM or threat intelligence platform for alerting and blocking.
  • Monitor network traffic for connections to the domains and URL listed in the iocs section, specifically looking for suspicious outbound connections.
  • Deploy the Sigma rule provided below to detect DNS queries to Kimsuky infrastructure.
  • Investigate any systems that have communicated with the IOCs from this report, prioritizing systems belonging to users involved in South Korean foreign policy, national security, or defense.

Detection coverage 2

Detect DNS Queries to Kimsuky Domains

medium

Detects DNS queries to domains associated with the Kimsuky APT group.

sigma tactics: command_and_control techniques: T1071.004 sources: dns_query, windows

Detect Outbound Connection to Kimsuky Domains

medium

Detects outbound network connections to domains associated with the Kimsuky APT group.

sigma tactics: command_and_control techniques: T1071.001 sources: network_connection, windows

Detection queries are available on the platform. Get full rules →

Indicators of compromise

49

domain

1

url

TypeValue
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f04e78fc9e109400f740b2e34c86ad5630c7048a
domain0jr87375qt.v6.navy
domain2ecy51395u.v6.navy
domainb8fq9189g6.dns.navy
domainconfirm1.moois-nid.remotewire.net
domaincxmfcubfnq.dns.navy
domaindiaxwn61lp.dynv6.net
domaindns-setup.remotewire.net
domaine639kk.wjyx49u3cu3.dns.army
domainegbzqa25gw.v6.navy
domainhealth-doc.giize.com
domaininfo.dns-setup.remotewire.net
domainip-cloud.theworkpc.com
domainips-doc.webredirect.org
domainips.dynuddns.net
domainispd.nts-write.remotewire.net
domainjbyaa6xotk.v6.army
domainlopm.webredirect.org
domainmois-doc.roxa.org
domainmois.mytunnel.org
domainmoois-nid.remotewire.net
domainms-cloud.ezgateway.net
domainmybox.camdvr.org
domainn-corp.hets12ex.dns.army
domainn2gdnw08p4.dns.navy
domainnav-log.moois-nid.remotewire.net
domainnaver.mywire.org
domainncodcnpass.dns.navy
domainnd8f3lxih4.v6.navy
domainndoc.nid-sign.opik.net
domainnid-nver.mybox.camdvr.org
domainnid-sign.opik.net
domainnid.ips-doc.webredirect.org
domainnid.naver.mywire.org
domainnid.ncodcnpass.dns.navy
domainnid.nid-sign.opik.net
domainnid.niws.mysynology.net
domainnid.puoios.o-r.kr
domainniws.mysynology.net
domainnj1oayuy2o.dns.army
domainnps-load.remotewire.net
domainnst.mysynology.net
domainnts-write.remotewire.net
domainnudoc-check.e639kk.wjyx49u3cu3.dns.army
domainnusrauth.gleeze.com
domainpassnid.lopm.webredirect.org
domainpuoios.o-r.kr
domainr461wn14u1.dns.army
domainsupport.nst.mysynology.net
domaintahpuoto94.dns.army