국세청 사칭 북한의 해킹 그룹 Konni(코니)에서 만든 악성코드-부가가치세 수정신고 안내(부가가치세사무처리규정).hwp(2024..6.27).lnk

2024-07-04 Sakai Konni Malware Disguised as a National Tax Service VAT Correction Notice LNK

https://wezard4u.tistory.com/429221

Thumbnail for 국세청 사칭 북한의 해킹 그룹 Konni(코니)에서 만든 악성코드-부가가치세 수정신고 안내(부가가치세사무처리규정).hwp(2024..6.27).lnk

A Korean-language analysis describes a Konni-linked malware lure impersonating South Korea's National Tax Service with a VAT correction notice delivered as an HWP-named Windows LNK. The oversized shortcut runs obfuscated PowerShell, searches for a matching LNK, extracts XOR-encoded payloads, writes a CAB under Public, expands it into Public\documents, and launches start.vbs for the next stage. The write-up provides hashes for the LNK and notes tax-agency impersonation and shortcut-based delivery against Korean-speaking users, while framing Konni as a North Korea-linked cluster associated with Thallium/APT37 and possibly Kimsuky.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e8b471c3d383fd44e53029676df3370… 2024-07-04 2024-07-04
HASH 6eee6fa92a270b1f32390eec50512eea 2024-07-04 2024-07-04
HASH 183fb85fc915017104cd473f8f3ad51… 2024-07-04 2024-07-04
URL http://stvse.com/upload.php 2024-07-04 2024-07-04
DOMAIN stvse.com 2024-07-04 2024-07-04

Related Actors

Related Reports

« Back