본문 바로가기
  • Home

Detection and Verification of Cryptocurrency Activities from Unstructured Data in Kimsuky and Prack Leak Analysis

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2025, 30(12), pp.215~225
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : November 24, 2025
  • Accepted : December 16, 2025
  • Published : December 31, 2025

Hyewon Lee 1 Donghyun Yeo 1 Minwon Seo 1

1에이아이스페라

Accredited

ABSTRACT

In late 2024, large-scale data leaked from cyberattacks linked to the Chinese and North Korean hacker group Kimsuky and the Prack incident included unstructured information such as government logs, source code, and browser timelines from the Ministry of Foreign Affairs and the Defense Counterintelligence Command. This study analyzes whether the attackers conducted financial activities using cryptocurrencies. Automatic identification of valid crypto addresses in large text datasets is challenging, as simple regex detection yields high false positives. To overcome this, we implemented a four-stage pipeline: (1) multi-coin regex detection, (2) checksum and decoding validation, (3) contextual scoring, and (4) on-chain verification. Experiments using approximately 80 MB of leaked data and Ethereum records from Etherscan reduced false positives by 75%, doubled true detections, and achieved an average processing time under three minutes. In particular, Ethereum address 0xb211b4...0cb6 appeared both in browser logs and on-chain deposits, confirming that the attacker viewed and analyzed blockchain assets. This research demonstrates a practical methodology for reconstructing blockchain activities from unstructured data in state-sponsored hacking cases.

Citation status

* References for papers published after 2024 are currently being built.