북한 Konni(코니) 에서 만든 한국인터넷진흥원 사칭 악성코드-KISA 알림.pdf.lnk(2025.5.8)

2025-05-13 Sakai Malware Created by North Korean Konni Impersonating the Korea Internet & Security Agency - KISA Notice.pdf.lnk (2025.5.8)

http://wezard4u.tistory.com/429485

Thumbnail for 북한 Konni(코니) 에서 만든 한국인터넷진흥원 사칭 악성코드-KISA 알림.pdf.lnk(2025.5.8)

Konni is linked to a malicious Windows shortcut disguised as a KISA notification PDF that appears designed to exploit public concern around a recent SK Telecom breach. The shortcut abuses mshta.exe to run obfuscated JavaScript that launches PowerShell, writes temporary files under ProgramData, and establishes a reverse-shell style loop. The PowerShell logic connects to 64.20.59.148 on port 7711, sends an infection identifier, receives one-line commands, saves them as a temporary script, executes them, deletes the script, and repeats every 20 seconds. The write-up notes the same IP was used in an earlier Konni impersonation case, making the infrastructure and LNK tradecraft useful for defenders tracking repeated DPRK-linked social-engineering operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 676ddf398f9afbbc583057904579de21 2025-05-13 2025-05-13
HASH 7d997e913766c9b9d163405ce4572ba… 2025-05-13 2025-05-13
HASH cf9d55508350adeee30606ebb3c31ad… 2025-05-13 2025-05-13
DOMAIN stem.net 2025-05-13 2025-05-13
IPv4 64.20.59.148 2025-02-26 2025-05-13
DOMAIN stem.io 2024-05-22 2025-05-13

Related Actors

Related Reports

« Back