북한 코니(Konni)KB국민은행 외국환거래 소명자료 제출서 위장한 악성코드-소명자료 제출 안내서(2025.5.13)

2025-05-26 Sakai namestring: hwp File

https://wezard4u.tistory.com/429495

Thumbnail for 북한 코니(Konni)KB국민은행 외국환거래 소명자료 제출서 위장한 악성코드-소명자료 제출 안내서(2025.5.13)

Konni activity is described using a KB Kookmin Bank foreign-exchange transaction explanation lure that delivers a malicious LNK named like an HWP document. The LNK runs obfuscated PowerShell to locate a specific-size LNK, decrypt embedded data with single-byte XOR keys, write a CAB file under Public Documents, expand it, and execute follow-on scripts. The batch/VBS chain establishes persistence through the HKCU Run key, downloads additional payloads from a WordPress path on rayanlynch.com, and can retrieve host-specific CAB content based on the computer name. The malware also collects directory listings from Downloads, Documents, and Desktop plus systeminfo output, then uploads the results to an external PHP endpoint, making the campaign relevant for Korean users handling banking or foreign-exchange documents.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 6a4c3256ff063f67d3251d6dd8229931 2025-05-26 2026-01-18
URL https://www.rayanlynch.com/wp-i… 2025-05-26 2026-01-14
URL https://www.rayanlynch.com/wp-i… 2025-05-26 2026-01-14
URL https://www.rayanlynch.com/wp-i… 2025-05-26 2026-01-14
HASH 135696c7a5b543ce2ab4a6aac7615d4… 2025-05-26 2025-05-26
HASH 305246b52f043f021761f7010fe5794… 2025-05-26 2025-05-26

Related Actors

Related Reports

« Back