북한 해킹 단체 코니(Konni) 에서 만든 악성코드-가상자산사업자 자금세탁방지 감독 방향(2025.2.18)
2025-02-24 • Sakai • Malware Created by the North Korean Hacking Group Konni - Direction for Anti-Money Laundering Supervision of Virtual Asset Service Providers (2025.2.18) •
The excerpt attributes a malicious LNK file themed around virtual asset service provider anti-money-laundering supervision to the North Korea-linked Konni group. The file, identified by SHA-256 4a6c23e76524364fe9b9f5ecd46dc73e7714cac93849a380f0d1b746fae3650d, disguises itself as an HWP-related shortcut while embedding obfuscated PowerShell. The script searches for PowerShell, locates a specially sized LNK file, extracts XOR-encoded payloads from fixed offsets, writes them under Public Documents, expands a CAB archive, deletes staging artifacts, and runs start.vbs. Follow-on batch scripts establish persistence through the HKCU Run key, download an encrypted ZIP from vetilministry.com, collect directory listings and system information, and upload the data to kerkenraad.com. The behavior shows a Konni-themed initial-access and staging chain combining LNK payload hiding, PowerShell and VBScript execution, persistence, downloader activity, and host reconnaissance.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4a6c23e76524364fe9b9f5ecd46dc73… | 2025-02-24 | 2025-02-24 |
| HASH | c09d17e968b250cadd66ec000d656d19 | 2025-02-24 | 2025-02-24 |
| HASH | 11f11d2ae39a35e433fe9c8f1b6a797… | 2025-02-24 | 2025-02-24 |
| URL | https://vetilministry.com/bg/wp… | 2025-02-24 | 2025-02-24 |
| URL | http://vetilministry.com/bg/wp-… | 2025-02-24 | 2025-02-24 |
| URL | https://vetilministry.com/bg/wp… | 2025-02-24 | 2025-02-24 |
| URL | http://vetilministry.com/bg/wp-… | 2025-02-24 | 2025-02-24 |
| URL | http://kerkenraad.com/src/uploa… | 2025-02-24 | 2025-02-24 |
| URL | http://kerkenraad.com/src/list.… | 2025-02-24 | 2025-02-24 |
| DOMAIN | kerkenraad.com | 2025-02-24 | 2025-02-24 |
| DOMAIN | vetilministry.com | 2025-02-24 | 2025-02-24 |