북한 코니(Konni)KB국민은행 외국환거래 소명자료 제출서 위장한 악성코드-소명자료 제출 안내서(2025.5.13)
2025-05-26 • Sakai • namestring: hwp File •
Konni activity is described using a KB Kookmin Bank foreign-exchange transaction explanation lure that delivers a malicious LNK named like an HWP document. The LNK runs obfuscated PowerShell to locate a specific-size LNK, decrypt embedded data with single-byte XOR keys, write a CAB file under Public Documents, expand it, and execute follow-on scripts. The batch/VBS chain establishes persistence through the HKCU Run key, downloads additional payloads from a WordPress path on rayanlynch.com, and can retrieve host-specific CAB content based on the computer name. The malware also collects directory listings from Downloads, Documents, and Desktop plus systeminfo output, then uploads the results to an external PHP endpoint, making the campaign relevant for Korean users handling banking or foreign-exchange documents.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 6a4c3256ff063f67d3251d6dd8229931 | 2025-05-26 | 2026-01-18 |
| URL | https://www.rayanlynch.com/wp-i… | 2025-05-26 | 2026-01-14 |
| URL | https://www.rayanlynch.com/wp-i… | 2025-05-26 | 2026-01-14 |
| URL | https://www.rayanlynch.com/wp-i… | 2025-05-26 | 2026-01-14 |
| HASH | 135696c7a5b543ce2ab4a6aac7615d4… | 2025-05-26 | 2025-05-26 |
| HASH | 305246b52f043f021761f7010fe5794… | 2025-05-26 | 2025-05-26 |