북한 해킹 그룹인 Konni(코니)로 추정 이 되는 2024년 북한인권 민간단체 전략활동 지원사업 신청서.lnk(2024.6.11)

2024-06-21 Sakai Malicious Konni LNK Disguised as a 2024 North Korean Human Rights NGO Support Application

http://wezard4u.tistory.com/6839

Thumbnail for 북한 해킹 그룹인 Konni(코니)로 추정 이 되는 2024년 북한인권 민간단체 전략활동 지원사업 신청서.lnk(2024.6.11)

The source analyzes a malicious LNK file assessed as likely Konni activity and disguised as a 2024 application form for North Korean human-rights civic-organization strategic activity support. The shortcut runs heavily obfuscated PowerShell, searches for a matching LNK file, extracts embedded byte ranges, writes and opens a decoy HWPX document, then drops and expands a CAB file under a MicrosoftEdge-themed ProgramData path. The extracted batch logic creates a scheduled task named MicrosoftEdgeEasyUpdate to run every 13 minutes, supporting persistence through a Temp-based batch file. Additional components appear to collect host and user-environment data such as computer name, desktop file listings, document file listings, whoami, systeminfo, and ipconfig output, with referenced infrastructure including a Cafe24-hosted domain and IP address. The lure theme and likely Konni attribution make the activity relevant to DPRK-linked targeting of Korean civil-society and North Korea human-rights communities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4f069b3c3d4ecf90a7f8a3836ac957d… 2024-06-21 2024-06-21
HASH cfffb45df8f05d1cb5d9d95fd5a83e9e 2024-06-21 2024-06-21
HASH 00b6a18a47bdecbf3f97e0a9188e008… 2024-06-21 2024-06-21
URL https://company536.cafe24.com/ 2024-06-21 2024-06-21
DOMAIN company536.cafe24.com 2024-06-21 2024-06-21
IPv4 183.111.174.68 2024-06-21 2024-06-21

Related Actors

Related Reports

« Back