북한발 사이버 공격과 코니(Konni)의 공격 아티팩트 분석
2024-10-08 • Igloo • Analysis of North Korean Cyberattacks and Konni Attack Artifacts •
IGLOO reviews North Korea-linked intrusion clusters including Kimsuky, Lazarus, and Konni, explaining how vendors map overlapping malware, tactics, and naming schemes into actor clusters such as APT37, APT38, Chollima-branded groups, and Microsoft weather-themed names. The report focuses on Konni as a cluster historically associated with Konni RAT and malicious-email delivery, noting activity observed since at least 2014 and campaigns against Russia, South Korea, and related targets using attachments such as screen-saver files. It frames the artifact analysis as a defensive aid for classifying DPRK threat activity and comparing actor tradecraft across public reporting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://cyb3rops.medium.com/the… | 2024-10-08 | 2025-03-05 |
| DOMAIN | cyb3rops.medium.com | 2024-10-08 | 2025-03-05 |
| HASH | 9d6c79c0b395cceb83662aa3f7ed0123 | 2024-05-06 | 2024-10-30 |
| HASH | 1bfe8d93ca1b2711fcf9958aa907abac | 2024-10-08 | 2024-10-08 |
| HASH | 7bb236041b91d4cd4fa129267cf109c3 | 2024-08-22 | 2024-10-08 |