북한 해킹 단체 Konni(코니) 에서 만든 악성코드-북한 내부정보시장통제 관련 내부 동향 및 물가.hwp.lnk(2024.4.4)

2024-04-12 Sakai Malware Created by the North Korean Hacking Group Konni - Internal Trends and Prices Related to North Korean Internal Information Market Control.hwp.lnk (2024.4.4)

https://wezard4u.tistory.com/6785

Thumbnail for 북한 해킹 단체 Konni(코니) 에서 만든 악성코드-북한 내부정보시장통제 관련 내부 동향 및 물가.hwp.lnk(2024.4.4)

Konni is reported using a malicious LNK file disguised as a Hangul Word Processor document about North Korean internal market controls and price trends. The source says the file is designed to look like an HWP attachment, but execution launches PowerShell-based activity instead, making it relevant to shortcut-abuse, document-lure, and script-execution detections. The report includes hashes for the sample and discusses how the lure and filename support social engineering around North Korea-related policy or internal-information themes. Defenders should validate the listed hashes, command-line behavior, and shortcut metadata against endpoint telemetry before operationalizing any indicators.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ba59f1ece68fa051400fd46467b0dc0… 2024-04-12 2024-10-30
HASH 3334d2605c0df26536058f73a43cb074 2024-04-12 2024-08-22
URL https://www.cammirando.com/wp-a… 2024-04-12 2024-08-22
HASH ebcd247c5ff2babe6ad1f001b482754… 2024-04-12 2024-04-12
URL https://www.cammirando.com/wp-a… 2024-04-12 2024-04-12
DOMAIN irando.com 2024-04-12 2024-04-12

Related Actors

Related Reports

« Back