북한 코니(KONNI)에서 만든 악성코드-가상자산사업자+검사계획민당정회의+발표자료_FN2.hwp.lnk(2025.1.23)
2025-02-20 • Sakai • Malware Created by North Korea's KONNI - Virtual Asset Service Provider Inspection Plan Party-Government-Council Presentation Materials_FN2.hwp.lnk (2025.1.23) •
The sample is attributed in the source to North Korea's KONNI group and uses a large Windows shortcut disguised as a virtual-asset business inspection and party-government meeting HWP document. The LNK launches obfuscated PowerShell that searches for a PowerShell executable, locates the matching shortcut by size, XOR-decrypts embedded payloads, drops files under C:\Users\Public\Documents, and executes follow-on VBS and batch components. The chain downloads a password-protected ZIP payload from teamfuels[.]com and uses batch and PowerShell upload routines to collect directory listings from Downloads, Documents, Desktop, and system information. Collected data is posted to forum.flasholr-app[.]com, giving operators host and file-inventory context that could support follow-on targeting in cryptocurrency or policy-adjacent environments.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://teamfuels.com/modules/i… | 2025-02-20 | 2026-01-14 |
| URL | http://forum.flasholr-app.com/w… | 2025-02-20 | 2026-01-14 |
| DOMAIN | teamfuels.com | 2025-02-20 | 2026-01-14 |
| DOMAIN | forum.flasholr-app.com | 2025-02-20 | 2026-01-14 |
| HASH | e37c8f6aba686aab3d7ecedbd1d0ef43 | 2025-02-14 | 2026-01-14 |
| DOMAIN | ystem.io | 2023-09-26 | 2025-08-21 |
| URL | https://teamfuels.com/modules/i… | 2025-02-20 | 2025-02-20 |
| DOMAIN | ohbwduthnvsz.co | 2025-02-20 | 2025-02-20 |
| HASH | 5a8ecafbd5809000334bf5b940a497d… | 2025-02-14 | 2025-02-20 |