북한발 사이버 공격과 코니(Konni)의 공격 아티팩트 분석

2024-10-08 Igloo Analysis of North Korean Cyberattacks and Konni Attack Artifacts

https://www.igloo.co.kr/security-information/%EB%B6%81%ED%95%9C%EB%B0%9C-%EC%82%AC%EC%9D%B4%EB%B2%84-%EA%B3%B5%EA%B2%A9%EA%B3%BC-%EC%BD%94%EB%8B%88konni%EC%9D%98-%EA%B3%B5%EA%B2%A9-%EC%95%84%ED%8B%B0%ED%8C%A9%ED%8A%B8-%EB%B6%84%EC%84%9D/

Thumbnail for 북한발 사이버 공격과 코니(Konni)의 공격 아티팩트 분석

IGLOO reviews North Korea-linked intrusion clusters including Kimsuky, Lazarus, and Konni, explaining how vendors map overlapping malware, tactics, and naming schemes into actor clusters such as APT37, APT38, Chollima-branded groups, and Microsoft weather-themed names. The report focuses on Konni as a cluster historically associated with Konni RAT and malicious-email delivery, noting activity observed since at least 2014 and campaigns against Russia, South Korea, and related targets using attachments such as screen-saver files. It frames the artifact analysis as a defensive aid for classifying DPRK threat activity and comparing actor tradecraft across public reporting.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://cyb3rops.medium.com/the… 2024-10-08 2025-03-05
DOMAIN cyb3rops.medium.com 2024-10-08 2025-03-05
HASH 9d6c79c0b395cceb83662aa3f7ed0123 2024-05-06 2024-10-30
HASH 1bfe8d93ca1b2711fcf9958aa907abac 2024-10-08 2024-10-08
HASH 7bb236041b91d4cd4fa129267cf109c3 2024-08-22 2024-10-08

Related Actors

Related Reports

« Back