북한 해킹 단체 코니(Konni) 에서 만든 악성코드-가상자산사업자 자금세탁방지 감독 방향(2025.2.18)

2025-02-24 Sakai Malware Created by the North Korean Hacking Group Konni - Direction for Anti-Money Laundering Supervision of Virtual Asset Service Providers (2025.2.18)

https://wezard4u.tistory.com/429413

Thumbnail for 북한 해킹 단체 코니(Konni) 에서 만든 악성코드-가상자산사업자 자금세탁방지 감독 방향(2025.2.18)

The excerpt attributes a malicious LNK file themed around virtual asset service provider anti-money-laundering supervision to the North Korea-linked Konni group. The file, identified by SHA-256 4a6c23e76524364fe9b9f5ecd46dc73e7714cac93849a380f0d1b746fae3650d, disguises itself as an HWP-related shortcut while embedding obfuscated PowerShell. The script searches for PowerShell, locates a specially sized LNK file, extracts XOR-encoded payloads from fixed offsets, writes them under Public Documents, expands a CAB archive, deletes staging artifacts, and runs start.vbs. Follow-on batch scripts establish persistence through the HKCU Run key, download an encrypted ZIP from vetilministry.com, collect directory listings and system information, and upload the data to kerkenraad.com. The behavior shows a Konni-themed initial-access and staging chain combining LNK payload hiding, PowerShell and VBScript execution, persistence, downloader activity, and host reconnaissance.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4a6c23e76524364fe9b9f5ecd46dc73… 2025-02-24 2025-02-24
HASH c09d17e968b250cadd66ec000d656d19 2025-02-24 2025-02-24
HASH 11f11d2ae39a35e433fe9c8f1b6a797… 2025-02-24 2025-02-24
URL https://vetilministry.com/bg/wp… 2025-02-24 2025-02-24
URL http://vetilministry.com/bg/wp-… 2025-02-24 2025-02-24
URL https://vetilministry.com/bg/wp… 2025-02-24 2025-02-24
URL http://vetilministry.com/bg/wp-… 2025-02-24 2025-02-24
URL http://kerkenraad.com/src/uploa… 2025-02-24 2025-02-24
URL http://kerkenraad.com/src/list.… 2025-02-24 2025-02-24
DOMAIN kerkenraad.com 2025-02-24 2025-02-24
DOMAIN vetilministry.com 2025-02-24 2025-02-24

Related Actors

Related Reports

« Back