북한 해킹 그룹인 Konni(코니)로 추정 이 되는 2024년 북한인권 민간단체 전략활동 지원사업 신청서.lnk(2024.6.11)
2024-06-21 • Sakai • Malicious Konni LNK Disguised as a 2024 North Korean Human Rights NGO Support Application •
The source analyzes a malicious LNK file assessed as likely Konni activity and disguised as a 2024 application form for North Korean human-rights civic-organization strategic activity support. The shortcut runs heavily obfuscated PowerShell, searches for a matching LNK file, extracts embedded byte ranges, writes and opens a decoy HWPX document, then drops and expands a CAB file under a MicrosoftEdge-themed ProgramData path. The extracted batch logic creates a scheduled task named MicrosoftEdgeEasyUpdate to run every 13 minutes, supporting persistence through a Temp-based batch file. Additional components appear to collect host and user-environment data such as computer name, desktop file listings, document file listings, whoami, systeminfo, and ipconfig output, with referenced infrastructure including a Cafe24-hosted domain and IP address. The lure theme and likely Konni attribution make the activity relevant to DPRK-linked targeting of Korean civil-society and North Korea human-rights communities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4f069b3c3d4ecf90a7f8a3836ac957d… | 2024-06-21 | 2024-06-21 |
| HASH | cfffb45df8f05d1cb5d9d95fd5a83e9e | 2024-06-21 | 2024-06-21 |
| HASH | 00b6a18a47bdecbf3f97e0a9188e008… | 2024-06-21 | 2024-06-21 |
| URL | https://company536.cafe24.com/ | 2024-06-21 | 2024-06-21 |
| DOMAIN | company536.cafe24.com | 2024-06-21 | 2024-06-21 |
| IPv4 | 183.111.174.68 | 2024-06-21 | 2024-06-21 |