북한 APT Konni(코니)에서 만든 악성코드-1. 알티피_엔지니어링본부 사업개발회의 자료.hwp.lnk(2024.6.28)

2024-11-10 Sakai Malware Created by North Korea's APT Konni - 1. RTP Engineering Headquarters Business Development Meeting Materials.hwp.lnk (2024.6.28)

https://wezard4u.tistory.com/429325

Thumbnail for 북한 APT Konni(코니)에서 만든 악성코드-1. 알티피_엔지니어링본부 사업개발회의 자료.hwp.lnk(2024.6.28)

The source analyzes a Konni-linked Windows LNK malware sample using an HWP-themed lure named for engineering business-development meeting materials. The report records MD5, SHA-1, and SHA-256 hashes and describes an execution chain involving embedded PowerShell and AutoIt script behavior, with the compiled payload reading commands and performing malicious actions on Windows systems. The activity fits DPRK-aligned social-engineering tradecraft that disguises malware as Korean document content while relying on script interpreters and shortcut execution.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://cavasa.com.co/webpyp/wp… 2024-11-10 2024-11-10
HASH 87dc4c8f67cffc8a9699328face923e2 2024-07-12 2024-11-10
HASH c5d67fb97a7a824168c872f8557eb52… 2024-07-12 2024-11-10
HASH 0aaec376904434197bae4f1a10ecfe8… 2024-07-08 2024-11-10

Related Actors

Related Reports

« Back