북한 해킹 단체 Konni APT(Advanced Persistant Threat) 만든 악성코드-오류발견 수정신고 제출 요청 안내(국세징수법 시행규칙).hwp.lnk(2025.1.7)
2025-01-24 • Sakai • Konni APT Malware Disguised as a Tax Collection Act Correction Request LNK File •
The Korean analysis attributes a tax-collection correction request-themed `.hwp.lnk` sample to Konni APT, a North Korean-linked group described as targeting government and organizational victims in South Korea and the United States. The LNK command searches for PowerShell, runs obfuscated script logic, XOR-decrypts embedded content with keys including `0x2B` and `0x72`, extracts a CAB payload, launches a VBS script from `C:\Users\Public\Documents`, and removes artifacts to hinder analysis. Follow-on batch activity collects file listings from Downloads, Documents, and Desktop along with system information, then uploads the results to `subscheme.info` with host-specific filenames. The excerpt identifies persistence and staging artifacts such as `start.vbs`, `elsewhere.cab`, `rshell.exe`, and upload/list PHP paths, showing an intrusion chain focused on reconnaissance, file discovery, and data exfiltration from Korean victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | stem.io | 2024-05-22 | 2025-05-13 |
| URL | http://subscheme.info/list.php?… | 2025-01-24 | 2025-01-24 |
| URL | http://subscheme.info/list.php?… | 2025-01-24 | 2025-01-24 |
| DOMAIN | hvil-telegram.org | 2025-01-15 | 2025-01-24 |
| HASH | c8556d5dd6383b600a459a531beb05ff | 2025-01-07 | 2025-01-24 |
| HASH | 3024b5438f5d63cdedb1c473cba07b1… | 2025-01-07 | 2025-01-24 |
| HASH | 4cd7e92ac6a3d068683d41beabd82d8… | 2025-01-07 | 2025-01-24 |
| URL | http://subscheme.info/upload.php | 2025-01-07 | 2025-01-24 |
| DOMAIN | subscheme.info | 2025-01-07 | 2025-01-24 |