북한 Konni(코니) 에서 만든 한국인터넷진흥원 사칭 악성코드-KISA 알림.pdf.lnk(2025.5.8)
2025-05-13 • Sakai • Malware Created by North Korean Konni Impersonating the Korea Internet & Security Agency - KISA Notice.pdf.lnk (2025.5.8) •
Konni is linked to a malicious Windows shortcut disguised as a KISA notification PDF that appears designed to exploit public concern around a recent SK Telecom breach. The shortcut abuses mshta.exe to run obfuscated JavaScript that launches PowerShell, writes temporary files under ProgramData, and establishes a reverse-shell style loop. The PowerShell logic connects to 64.20.59.148 on port 7711, sends an infection identifier, receives one-line commands, saves them as a temporary script, executes them, deletes the script, and repeats every 20 seconds. The write-up notes the same IP was used in an earlier Konni impersonation case, making the infrastructure and LNK tradecraft useful for defenders tracking repeated DPRK-linked social-engineering operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 676ddf398f9afbbc583057904579de21 | 2025-05-13 | 2025-05-13 |
| HASH | 7d997e913766c9b9d163405ce4572ba… | 2025-05-13 | 2025-05-13 |
| HASH | cf9d55508350adeee30606ebb3c31ad… | 2025-05-13 | 2025-05-13 |
| DOMAIN | stem.net | 2025-05-13 | 2025-05-13 |
| IPv4 | 64.20.59.148 | 2025-02-26 | 2025-05-13 |
| DOMAIN | stem.io | 2024-05-22 | 2025-05-13 |