북한 코니(Konni)에서 제작한 것으로 추측 되는 악성코드 우리은행 사용자 노린 악성코드 WooriCard_20231108.html.lnk(2025.5.19)

2025-07-07 Sakai Malware Suspected to Have Been Created by North Korean Konni, Targeting Woori Bank Users - WooriCard_20231108.html.lnk (2025.5.19)

https://wezard4u.tistory.com/429529

Thumbnail for 북한 코니(Konni)에서 제작한 것으로 추측 되는 악성코드 우리은행 사용자 노린 악성코드 WooriCard_20231108.html.lnk(2025.5.19)

A WooriCard-themed LNK sample is assessed by the source as likely Konni-linked, with caution, and is aimed at users of Woori Bank/Woori Card security-mail workflows. The shortcut runs obfuscated batch logic to launch hidden PowerShell, locate a specifically sized LNK file, extract an embedded WooriCard_20231108.html phishing page, and display a fake encrypted mail prompt requesting birthdate or business-registration information. A second embedded payload is expanded from a CAB file into C:\Users\Public\Libraries and runs avtue483.bat, which inventories files from Desktop, Documents, Downloads, Music, Pictures, and Videos. The excerpt also describes an upload helper that posts collected files with the computer name to a remote data endpoint, making the lure both a credential-phishing and host-reconnaissance chain.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7672a9bf5a58e2c17925dbb759ea98ce 2025-07-07 2026-01-14
HASH ac56bdd7cead82ede6690355e7c9924… 2025-07-07 2025-07-07
HASH 50826fc1142a3442c04576c68478eab… 2025-07-07 2025-07-07

Related Actors

Related Reports

« Back