북한 해킹 단체 Konni(코니)에서는 만든 업비트 사칭 악성코드-첨부1_성명_개인정보수집이용동의서.docx.lnk(2024.03.07)

2024-03-11 Sakai Upbit impersonation malware created by North Korean hacking group Konni - Attachment 1_Statement_Personal Information Collection and Use Agreement.docx.lnk (2024.03.07)

https://wezard4u.tistory.com/6754

A Korean write-up analyzes malware attributed by the author to the North Korean Konni group and disguised as an Upbit-related document package. The attack uses a ZIP archive containing a malicious LNK named like a personal-information consent DOCX file and a decoy mail-reference file; opening the LNK launches heavily obfuscated PowerShell. The script extracts embedded data from the shortcut, writes a DOCX and a CAB file under public locations, expands the archive, runs VBS and batch components, and proceeds with follow-on execution and cleanup. The evidence supports Konni-linked cryptocurrency-themed social engineering and a PowerShell/LNK delivery chain rather than a broader claim about confirmed theft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 27cd090cf83877750416d37dc6ddd8f… 2024-03-11 2024-06-17
URL https://goosess.com/read/get.php 2024-03-11 2024-06-17
DOMAIN stuckss.com 2024-03-11 2024-06-17
DOMAIN goosess.com 2024-03-11 2024-06-17
HASH 655893b1641565f8ea04da4d74116b8a 2024-03-11 2024-03-26
URL http://stuckss.com/list.php 2024-03-11 2024-03-26
URL http://stuckss.com/upload.php 2024-03-11 2024-03-26
HASH 0d1383c289d511acd9d8d8644c224c61 2024-03-11 2024-03-11
HASH 8e7bd31ba55449c888d3b013612f539a 2024-03-11 2024-03-11
HASH ca64ca50a07e1936fe00f2ff8509f03… 2024-03-11 2024-03-11

Related Actors

Related Reports

« Back