국세청 사칭 북한 코니(Konni) 에서 제작한 해외금융계좌 신고서.hwp.lnk(2025.7.25)

2025-08-08 Sakai Foreign financial account declaration HWP.LNK produced by North Korean Konni impersonating the National Tax Service

https://wezard4u.tistory.com/429562

Thumbnail for 국세청 사칭 북한 코니(Konni) 에서 제작한 해외금융계좌 신고서.hwp.lnk(2025.7.25)

A Konni-attributed LNK malware sample impersonates a Korean National Tax Service overseas financial account declaration form and abuses Windows PowerShell to unpack and run embedded payloads. The obfuscated script searches for a matching .lnk file by size, extracts XOR-encoded data from fixed offsets, writes a payload, expands a CAB file under Public Documents, deletes staging files, and launches a VBS script. Follow-on BAT components collect Downloads, Documents, Desktop directory listings and systeminfo output, then use an RC4-like routine and HTTP POST to upload data to mrtech-solutions.com/dashboard/storage/app/src/upload.php. The exposed server behavior described in the excerpt includes upload and listing endpoints plus Laravel debug exposure, making the campaign relevant for tracking Konni data-theft tradecraft and C2 infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8b8fa6c4298d83d78e11b52f22a79100 2025-08-08 2026-01-18
IPv4 217.60.37.55 2025-08-08 2025-08-11
HASH 33057c8c7f277e89872239907792f6f… 2025-08-08 2025-08-08
HASH 8d9d5a21d75e14410cc30e15176ecae… 2025-08-08 2025-08-08
URL https://mrtech-solutions.com/da… 2025-08-08 2025-08-08
DOMAIN mrtech-solutions.com 2025-08-08 2025-08-08

Related Actors

Related Reports

« Back