북한 해킹조직 코니(Konni) 위장문서 부가세납부서(국세징수법 시행규칙) 악용한 악성코드 유포(2025.4.28)

2025-05-05 Sakai North Korean Hacking Organization Konni Distributes Malware Abusing a Decoy Document, VAT Payment Notice (Enforcement Rules of the National Tax Collection Act) (2025.4.28)

https://wezard4u.tistory.com/429478

Thumbnail for 북한 해킹조직 코니(Konni) 위장문서 부가세납부서(국세징수법 시행규칙) 악용한 악성코드 유포(2025.4.28)

A Konni-attributed campaign used a malicious LNK disguised as a Korean VAT payment notice form with an HWP-style filename and icon. The LNK runs obfuscated PowerShell, searches for the embedded shortcut by size, extracts XOR-encoded payload data, expands a CAB archive into the Public Documents path, and executes follow-on scripts. The infection chain downloads a password-protected ZIP from deliberatecollaboration.com, unpacks batch files, and repeatedly attempts execution while deleting temporary files and other traces. The payload collects file listings from Downloads, Documents, and Desktop along with system information, then encrypts the collected text and uploads it by HTTP POST, supporting reconnaissance and information theft from infected Windows systems.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ystem.io 2023-09-26 2025-08-21
HASH 928ff0f4bd8cf4e2b6ba7f6fe0e3b49… 2025-05-05 2025-05-05
HASH bdd0438f00d760eb23ae707071672c8… 2025-05-05 2025-05-05
HASH 990c0f2ec42713e0f7d49458da7446f… 2025-05-05 2025-05-05
HASH 80e1758c0d6dcf5de932226958ba3361 2025-05-05 2025-05-05
HASH 68a92a2df9d7be6e36bc3efa7d37cebc 2025-05-05 2025-05-05
HASH 2d27304151fc8299288feb084640079… 2025-05-05 2025-05-05
URL https://deliberatecollaboration… 2025-05-05 2025-05-05
DOMAIN deliberatecollaboration.com 2025-05-05 2025-05-05

Related Actors

Related Reports

« Back