북한 코니(KONNI)에서 만든 악성코드-가상자산사업자+검사계획민당정회의+발표자료_FN2.hwp.lnk(2025.1.23)

2025-02-20 Sakai Malware Created by North Korea's KONNI - Virtual Asset Service Provider Inspection Plan Party-Government-Council Presentation Materials_FN2.hwp.lnk (2025.1.23)

https://wezard4u.tistory.com/429410

Thumbnail for 북한 코니(KONNI)에서 만든 악성코드-가상자산사업자+검사계획민당정회의+발표자료_FN2.hwp.lnk(2025.1.23)

The sample is attributed in the source to North Korea's KONNI group and uses a large Windows shortcut disguised as a virtual-asset business inspection and party-government meeting HWP document. The LNK launches obfuscated PowerShell that searches for a PowerShell executable, locates the matching shortcut by size, XOR-decrypts embedded payloads, drops files under C:\Users\Public\Documents, and executes follow-on VBS and batch components. The chain downloads a password-protected ZIP payload from teamfuels[.]com and uses batch and PowerShell upload routines to collect directory listings from Downloads, Documents, Desktop, and system information. Collected data is posted to forum.flasholr-app[.]com, giving operators host and file-inventory context that could support follow-on targeting in cryptocurrency or policy-adjacent environments.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://teamfuels.com/modules/i… 2025-02-20 2026-01-14
URL http://forum.flasholr-app.com/w… 2025-02-20 2026-01-14
DOMAIN teamfuels.com 2025-02-20 2026-01-14
DOMAIN forum.flasholr-app.com 2025-02-20 2026-01-14
HASH e37c8f6aba686aab3d7ecedbd1d0ef43 2025-02-14 2026-01-14
DOMAIN ystem.io 2023-09-26 2025-08-21
URL https://teamfuels.com/modules/i… 2025-02-20 2025-02-20
DOMAIN ohbwduthnvsz.co 2025-02-20 2025-02-20
HASH 5a8ecafbd5809000334bf5b940a497d… 2025-02-14 2025-02-20

Related Actors

Related Reports

« Back