Phrack's "APT Down": a leaked hacker workstation
Alleged: Reported or claimed; not established in the public record.
An article in Phrack described about 9GB of data said to have been taken in June 2025 from the workstation of a hacker who targeted South Korean systems. The authors alleged the operator was the North Korean group Kimsuky.
Confirmed
Intel 471 examined and described the published material.
Claimed, disputed or not established
S2W's summary said the operator is unlikely to be Kimsuky, tracked it as a separate cluster and noted extensive Chinese-language use. AhnLab's ASEC likewise described a Chinese-proficient corporate actor. The authors' attribution is disputed.
Reported impact
Researchers revised their attribution views; the case is cited as an example of an actor's identity being contested after a leak.
Source strength: The lazarus.day page is an aggregator of other firms' analyses, and the Phrack text itself was not read for this entry.
Sources (opened in a new tab)
- Intel 471: the Phrack leak, examining an APT's workstation ↗https://www.intel471.com/blog/the-phrack-leak-examining-an-apts-workstation
- AhnLab ASEC analysis ↗https://asec.ahnlab.com/en/90498/
- lazarus.day: summary of APT Down analyses ↗https://lazarus.day/reports/detailed-analysis-of-phracks-apt-down-the-north-korea-files-knl94/
Connected
- Related leaks: i-Soon leak: a Chinese hacking contractor
- Case board · Timeline (2025) · Document vault · How we verify leaks
This page describes and cites public reporting. It does not host or link to leaked files, and it names no private individuals.
