북한 코니(Konni)에서 제작한 것으로 추측 되는 악성코드 우리은행 사용자 노린 악성코드 WooriCard_20231108.html.lnk(2025.5.19)
2025-07-07 • Sakai • Malware Suspected to Have Been Created by North Korean Konni, Targeting Woori Bank Users - WooriCard_20231108.html.lnk (2025.5.19) •
A WooriCard-themed LNK sample is assessed by the source as likely Konni-linked, with caution, and is aimed at users of Woori Bank/Woori Card security-mail workflows. The shortcut runs obfuscated batch logic to launch hidden PowerShell, locate a specifically sized LNK file, extract an embedded WooriCard_20231108.html phishing page, and display a fake encrypted mail prompt requesting birthdate or business-registration information. A second embedded payload is expanded from a CAB file into C:\Users\Public\Libraries and runs avtue483.bat, which inventories files from Desktop, Documents, Downloads, Music, Pictures, and Videos. The excerpt also describes an upload helper that posts collected files with the computer name to a remote data endpoint, making the lure both a credential-phishing and host-reconnaissance chain.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7672a9bf5a58e2c17925dbb759ea98ce | 2025-07-07 | 2026-01-14 |
| HASH | ac56bdd7cead82ede6690355e7c9924… | 2025-07-07 | 2025-07-07 |
| HASH | 50826fc1142a3442c04576c68478eab… | 2025-07-07 | 2025-07-07 |