북한 APT Konni(코니)에서 만든 악성코드-1. 알티피_엔지니어링본부 사업개발회의 자료.hwp.lnk(2024.6.28)
2024-11-10 • Sakai • Malware Created by North Korea's APT Konni - 1. RTP Engineering Headquarters Business Development Meeting Materials.hwp.lnk (2024.6.28) •
The source analyzes a Konni-linked Windows LNK malware sample using an HWP-themed lure named for engineering business-development meeting materials. The report records MD5, SHA-1, and SHA-256 hashes and describes an execution chain involving embedded PowerShell and AutoIt script behavior, with the compiled payload reading commands and performing malicious actions on Windows systems. The activity fits DPRK-aligned social-engineering tradecraft that disguises malware as Korean document content while relying on script interpreters and shortcut execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://cavasa.com.co/webpyp/wp… | 2024-11-10 | 2024-11-10 |
| HASH | 87dc4c8f67cffc8a9699328face923e2 | 2024-07-12 | 2024-11-10 |
| HASH | c5d67fb97a7a824168c872f8557eb52… | 2024-07-12 | 2024-11-10 |
| HASH | 0aaec376904434197bae4f1a10ecfe8… | 2024-07-08 | 2024-11-10 |