북한 해킹 단체 Konni APT(Advanced Persistant Threat) 만든 악성코드-오류발견 수정신고 제출 요청 안내(국세징수법 시행규칙).hwp.lnk(2025.1.7)

2025-01-24 Sakai Konni APT Malware Disguised as a Tax Collection Act Correction Request LNK File

https://wezard4u.tistory.com/429389

Thumbnail for 북한 해킹 단체 Konni APT(Advanced Persistant Threat) 만든 악성코드-오류발견 수정신고 제출 요청 안내(국세징수법 시행규칙).hwp.lnk(2025.1.7)

The Korean analysis attributes a tax-collection correction request-themed `.hwp.lnk` sample to Konni APT, a North Korean-linked group described as targeting government and organizational victims in South Korea and the United States. The LNK command searches for PowerShell, runs obfuscated script logic, XOR-decrypts embedded content with keys including `0x2B` and `0x72`, extracts a CAB payload, launches a VBS script from `C:\Users\Public\Documents`, and removes artifacts to hinder analysis. Follow-on batch activity collects file listings from Downloads, Documents, and Desktop along with system information, then uploads the results to `subscheme.info` with host-specific filenames. The excerpt identifies persistence and staging artifacts such as `start.vbs`, `elsewhere.cab`, `rshell.exe`, and upload/list PHP paths, showing an intrusion chain focused on reconnaissance, file discovery, and data exfiltration from Korean victims.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN stem.io 2024-05-22 2025-05-13
URL http://subscheme.info/list.php?… 2025-01-24 2025-01-24
URL http://subscheme.info/list.php?… 2025-01-24 2025-01-24
DOMAIN hvil-telegram.org 2025-01-15 2025-01-24
HASH c8556d5dd6383b600a459a531beb05ff 2025-01-07 2025-01-24
HASH 3024b5438f5d63cdedb1c473cba07b1… 2025-01-07 2025-01-24
HASH 4cd7e92ac6a3d068683d41beabd82d8… 2025-01-07 2025-01-24
URL http://subscheme.info/upload.php 2025-01-07 2025-01-24
DOMAIN subscheme.info 2025-01-07 2025-01-24

Related Actors

Related Reports

« Back