북한 해킹조직 코니(Konni) 위장문서 부가세납부서(국세징수법 시행규칙) 악용한 악성코드 유포(2025.4.28)
2025-05-05 • Sakai • North Korean Hacking Organization Konni Distributes Malware Abusing a Decoy Document, VAT Payment Notice (Enforcement Rules of the National Tax Collection Act) (2025.4.28) •
A Konni-attributed campaign used a malicious LNK disguised as a Korean VAT payment notice form with an HWP-style filename and icon. The LNK runs obfuscated PowerShell, searches for the embedded shortcut by size, extracts XOR-encoded payload data, expands a CAB archive into the Public Documents path, and executes follow-on scripts. The infection chain downloads a password-protected ZIP from deliberatecollaboration.com, unpacks batch files, and repeatedly attempts execution while deleting temporary files and other traces. The payload collects file listings from Downloads, Documents, and Desktop along with system information, then encrypts the collected text and uploads it by HTTP POST, supporting reconnaissance and information theft from infected Windows systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ystem.io | 2023-09-26 | 2025-08-21 |
| HASH | 928ff0f4bd8cf4e2b6ba7f6fe0e3b49… | 2025-05-05 | 2025-05-05 |
| HASH | bdd0438f00d760eb23ae707071672c8… | 2025-05-05 | 2025-05-05 |
| HASH | 990c0f2ec42713e0f7d49458da7446f… | 2025-05-05 | 2025-05-05 |
| HASH | 80e1758c0d6dcf5de932226958ba3361 | 2025-05-05 | 2025-05-05 |
| HASH | 68a92a2df9d7be6e36bc3efa7d37cebc | 2025-05-05 | 2025-05-05 |
| HASH | 2d27304151fc8299288feb084640079… | 2025-05-05 | 2025-05-05 |
| URL | https://deliberatecollaboration… | 2025-05-05 | 2025-05-05 |
| DOMAIN | deliberatecollaboration.com | 2025-05-05 | 2025-05-05 |