Breakglass Intelligence identified a third Vultr Seoul VPS, 158.247.210.58, as part of a long-running Kimsuky/APT43 infrastructure cluster used to harvest credentials and deliver phishing lures against South Korean targets. The server has been tied to more than 60 domains over roughly 18 months, with naming patterns spoofing Naver, South Korea’s HomeTax service, and government portals. Passive DNS indicates the node may have been under actor control since at least 2020, and researchers said it rotated domains across multiple dynamic DNS providers—including mydns.vc, mydns.bz, mydns.jp, dynv6.net, dns.army, dns.navy, and kro.kr—to evade detection. Although web ports were closed or filtered at the time of reporting, 31 domains still resolved to the IP, suggesting the phishing node remained dormant but available for reactivation.
In a separate investigation, Breakglass said the NEKOBYTE adversary-in-the-middle proxy network expanded from about 300 to 1,004 confirmed servers in six weeks, largely within AS206134, and was configured to relay traffic with legitimate TLS certificates for more than 40 services including GitHub, Microsoft, Apple, Zoom, Twitch, kernel.org, MEGA, and DENIC. The researchers linked the infrastructure to NEKOBYTE INTERNATIONAL LIMITED, IT-Garage LLC, a Sevastopol-based operating entity, and Crimean IT figure Igor Tsimbal, and said the network spans 34 subnets and about 8,700 IPv4 addresses with geofeed locations in Frankfurt, Helsinki, and Moscow. A self-signed VK interm CA certificate associated with Russian DPI/SORM-style interception was cited as a strong indicator of possible Russian state-linked surveillance capability, while the presence of proxies for kernel.org, jsDelivr, Oracle Container Registry, and GitHub raised concerns about software supply-chain targeting.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
On April 21, 2026, Breakglass Intelligence reported that 158.247.210.58 belonged to the same Kimsuky/APT43 operational cluster as previously documented Vultr Seoul systems 158.247.219.150 and 158.247.250.37. The report highlighted a five-year infrastructure trail and long-term phishing activity against South Korean targets.
Researchers connected the NEKOBYTE operation to UK shell companies, a Sevastopol-based operating entity, and Igor Tsimbal, a Crimean IT figure allegedly involved with infrastructure for the Russian occupation government. They also identified a self-signed "VK interm CA" certificate that they assessed as a strong indicator of Russian state-linked DPI/SORM-style interception capability.
Breakglass Intelligence found the proxy network transparently relayed traffic using real TLS certificates for more than 40 services, including GitHub, Microsoft, Apple, Zoom, Twitch, kernel.org, MEGA, and DENIC. The setup enabled covert interception of credentials and session tokens and suggested possible supply-chain targeting through services such as kernel.org, jsDelivr, Oracle Container Registry, and GitHub.
As of April 20, 2026, web ports on 158.247.210.58 were closed or filtered, but 31 domains still resolved to the IP address. Researchers assessed the server as a dormant but readily reactivatable phishing node within the broader Kimsuky cluster.
On April 5, 2026, Breakglass Intelligence reported a separate Kimsuky/APT43 phishing cell using distinct domains and hosting from a previously documented cluster. The operation targeted webmail, Zoom, and Naver users and used a Telegram bot token for real-time credential exfiltration plus IPFS-hosted obfuscated JavaScript harvesters to complicate takedowns.
On 2026-04-03, Breakglass Intelligence reported a Kimsuky/APT43 phishing infrastructure centered on 158.247.219.150 that impersonated major South Korean institutions and services. Researchers documented 740 phishing hostnames, 49 registered domains, 98 sequential dynv6.net subdomains, South Korea-only geofencing, and one-time SMS token gating, indicating automated large-scale credential-harvesting operations.
On 2026-03-07, Breakglass Intelligence reported that a PostgreSQL credential-stuffing attempt from NEKOBYTE infrastructure led to the discovery of more than 300 TLS man-in-the-middle proxy hosts using genuine certificates to transparently intercept traffic for major services. The report also outlined a broader 22-ASN, 128,000+ IPv4 ecosystem tied to NEKOBYTE-linked entities and assessed the operation as consistent with Russian state surveillance infrastructure.
Passive DNS records indicate the Vultr Seoul server at 158.247.210.58 was under the control of a Kimsuky/APT43-linked infrastructure cluster by at least September 2020. Researchers later tied it to credential-harvesting and phishing activity targeting South Korean users.
Within six weeks, infrastructure tied to NEKOBYTE INTERNATIONAL LIMITED and IT-Garage LLC expanded from roughly 300 to 1,004 confirmed adversary-in-the-middle proxy servers. The operation was concentrated in AS206134 and spanned 34 subnets and about 8,700 IPv4 addresses.
Over an 18-month period, the Kimsuky-linked VPS was associated with more than 60 domains using multiple dynamic DNS providers including mydns.vc, mydns.bz, mydns.jp, dynv6.net, dns.army, dns.navy, and kro.kr. The domains impersonated Naver, South Korea's National Tax Service HomeTax platform, and Korean government portals as part of an evasion-focused phishing operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 211 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.