소송 관련 내용의 악성 한글 HWP 파일 유포 - 코니(KONNI) 조직
2019-12-12 • Ahnlab • Distribution of malicious Korean HWP files with lawsuit-related content - KONNI organization •
AhnLab reported a malicious HWP file tied to the Konni cluster and the Operation MoneyHolic activity set. The lure was presented as a legal response document for a private hospital lawsuit and contained a malicious PostScript object. Shellcode analysis led AhnLab to assess that the file was distributed by Konni or an Operation MoneyHolic-related actor. The report provides a file hash and execution-flow context useful for detecting HWP/PostScript delivery chains associated with Korean-language APT activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f5339239a6bcda0afe61e6ef8bfafe5… | 2019-12-12 | 2019-12-12 |
| HASH | bbde7c694faf6b450adbfc8efe88a41a | 2019-12-12 | 2019-12-12 |
Related Actors
Related Reports
Shares tag: Konni • Shares 1 IOC • Published within a week
2020-01-05 •
80% Match
#Konni
#T1082
#T1140
#T1112
#T1057
#T1059
#T1129
#T1134
#T1085
#T1050
#T1031
#T1088
Shares tag: Konni • Published within a month
Shares tag: Konni • Published within a month
Shares tag: Konni • Same author: Ahnlab
Shares tag: Konni • Same author: Ahnlab
Shares tag: Konni • Same author: Ahnlab