국세청 사칭 북한 코니(Konni) 에서 제작한 해외금융계좌 신고서.hwp.lnk(2025.7.25)
2025-08-08 • Sakai • Foreign financial account declaration HWP.LNK produced by North Korean Konni impersonating the National Tax Service •
A Konni-attributed LNK malware sample impersonates a Korean National Tax Service overseas financial account declaration form and abuses Windows PowerShell to unpack and run embedded payloads. The obfuscated script searches for a matching .lnk file by size, extracts XOR-encoded data from fixed offsets, writes a payload, expands a CAB file under Public Documents, deletes staging files, and launches a VBS script. Follow-on BAT components collect Downloads, Documents, Desktop directory listings and systeminfo output, then use an RC4-like routine and HTTP POST to upload data to mrtech-solutions.com/dashboard/storage/app/src/upload.php. The exposed server behavior described in the excerpt includes upload and listing endpoints plus Laravel debug exposure, making the campaign relevant for tracking Konni data-theft tradecraft and C2 infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8b8fa6c4298d83d78e11b52f22a79100 | 2025-08-08 | 2026-01-18 |
| IPv4 | 217.60.37.55 | 2025-08-08 | 2025-08-11 |
| HASH | 33057c8c7f277e89872239907792f6f… | 2025-08-08 | 2025-08-08 |
| HASH | 8d9d5a21d75e14410cc30e15176ecae… | 2025-08-08 | 2025-08-08 |
| URL | https://mrtech-solutions.com/da… | 2025-08-08 | 2025-08-08 |
| DOMAIN | mrtech-solutions.com | 2025-08-08 | 2025-08-08 |