북한 해킹 단체 Konni(코니)에서는 만든 업비트 사칭 악성코드-첨부1_성명_개인정보수집이용동의서.docx.lnk(2024.03.07)
2024-03-11 • Sakai • Upbit impersonation malware created by North Korean hacking group Konni - Attachment 1_Statement_Personal Information Collection and Use Agreement.docx.lnk (2024.03.07) •
A Korean write-up analyzes malware attributed by the author to the North Korean Konni group and disguised as an Upbit-related document package. The attack uses a ZIP archive containing a malicious LNK named like a personal-information consent DOCX file and a decoy mail-reference file; opening the LNK launches heavily obfuscated PowerShell. The script extracts embedded data from the shortcut, writes a DOCX and a CAB file under public locations, expands the archive, runs VBS and batch components, and proceeds with follow-on execution and cleanup. The evidence supports Konni-linked cryptocurrency-themed social engineering and a PowerShell/LNK delivery chain rather than a broader claim about confirmed theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 27cd090cf83877750416d37dc6ddd8f… | 2024-03-11 | 2024-06-17 |
| URL | https://goosess.com/read/get.php | 2024-03-11 | 2024-06-17 |
| DOMAIN | stuckss.com | 2024-03-11 | 2024-06-17 |
| DOMAIN | goosess.com | 2024-03-11 | 2024-06-17 |
| HASH | 655893b1641565f8ea04da4d74116b8a | 2024-03-11 | 2024-03-26 |
| URL | http://stuckss.com/list.php | 2024-03-11 | 2024-03-26 |
| URL | http://stuckss.com/upload.php | 2024-03-11 | 2024-03-26 |
| HASH | 0d1383c289d511acd9d8d8644c224c61 | 2024-03-11 | 2024-03-11 |
| HASH | 8e7bd31ba55449c888d3b013612f539a | 2024-03-11 | 2024-03-11 |
| HASH | ca64ca50a07e1936fe00f2ff8509f03… | 2024-03-11 | 2024-03-11 |