북한 해킹 단체 코니(Konni) 에서 만든 악성코드-가상자산 관련 외부평가위원 위촉 안내.hwp(2025.5.2)

2025-05-30 Sakai Malware Created by North Korean Hacking Group Konni - Notice of Appointment as External Evaluator for Virtual Assets.hwp (2025.5.2)

https://wezard4u.tistory.com/429498

Thumbnail for 북한 해킹 단체 코니(Konni) 에서 만든 악성코드-가상자산 관련 외부평가위원 위촉 안내.hwp(2025.5.2)

A Konni-attributed LNK masquerades as a Korean HWP notice about appointing external evaluators for virtual assets. The shortcut runs PowerShell through rshell.exe, searches for a specific-size LNK, extracts embedded payloads from fixed offsets, XOR-decodes them with keys including 0x71 and 0x70, executes the recovered file, unpacks agenda.cab, and deletes artifacts. Follow-on batch scripts register start.vbs under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, download a password-protected ZIP from a seacura.com WordPress path, unpack and execute 1.bat, and collect directory listings from user folders. The virtual-asset lure and downloader behavior make the activity relevant to Korean cryptocurrency and financial-sector targeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f9f3b762ed1719bf141c38f8c4f21d7… 2025-05-30 2025-05-30
HASH eb4e370782f214d376c6041a0614086… 2025-05-30 2025-05-30
HASH cbd734874b44e73ce155998db7e6663a 2025-05-30 2025-05-30
URL https://www.seacura.com/wp-incl… 2025-05-30 2025-05-30
URL https://www.seacura.com/wp-incl… 2025-05-30 2025-05-30

Related Actors

Related Reports

« Back