북한 해킹 단체 Konni(코니) 에서 만든 악성코드-북한 내부정보시장통제 관련 내부 동향 및 물가.hwp.lnk(2024.4.4)
2024-04-12 • Sakai • Malware Created by the North Korean Hacking Group Konni - Internal Trends and Prices Related to North Korean Internal Information Market Control.hwp.lnk (2024.4.4) •
Konni is reported using a malicious LNK file disguised as a Hangul Word Processor document about North Korean internal market controls and price trends. The source says the file is designed to look like an HWP attachment, but execution launches PowerShell-based activity instead, making it relevant to shortcut-abuse, document-lure, and script-execution detections. The report includes hashes for the sample and discusses how the lure and filename support social engineering around North Korea-related policy or internal-information themes. Defenders should validate the listed hashes, command-line behavior, and shortcut metadata against endpoint telemetry before operationalizing any indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | ba59f1ece68fa051400fd46467b0dc0… | 2024-04-12 | 2024-10-30 |
| HASH | 3334d2605c0df26536058f73a43cb074 | 2024-04-12 | 2024-08-22 |
| URL | https://www.cammirando.com/wp-a… | 2024-04-12 | 2024-08-22 |
| HASH | ebcd247c5ff2babe6ad1f001b482754… | 2024-04-12 | 2024-04-12 |
| URL | https://www.cammirando.com/wp-a… | 2024-04-12 | 2024-04-12 |
| DOMAIN | irando.com | 2024-04-12 | 2024-04-12 |