국세청 사칭 북한의 해킹 그룹 Konni(코니)에서 만든 악성코드-부가가치세 수정신고 안내(부가가치세사무처리규정).hwp(2024..6.27).lnk
2024-07-04 • Sakai • Konni Malware Disguised as a National Tax Service VAT Correction Notice LNK •
A Korean-language analysis describes a Konni-linked malware lure impersonating South Korea's National Tax Service with a VAT correction notice delivered as an HWP-named Windows LNK. The oversized shortcut runs obfuscated PowerShell, searches for a matching LNK, extracts XOR-encoded payloads, writes a CAB under Public, expands it into Public\documents, and launches start.vbs for the next stage. The write-up provides hashes for the LNK and notes tax-agency impersonation and shortcut-based delivery against Korean-speaking users, while framing Konni as a North Korea-linked cluster associated with Thallium/APT37 and possibly Kimsuky.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e8b471c3d383fd44e53029676df3370… | 2024-07-04 | 2024-07-04 |
| HASH | 6eee6fa92a270b1f32390eec50512eea | 2024-07-04 | 2024-07-04 |
| HASH | 183fb85fc915017104cd473f8f3ad51… | 2024-07-04 | 2024-07-04 |
| URL | http://stvse.com/upload.php | 2024-07-04 | 2024-07-04 |
| DOMAIN | stvse.com | 2024-07-04 | 2024-07-04 |