소송 관련 내용의 악성 한글 HWP 파일 유포 - 코니(KONNI) 조직

2019-12-12 Ahnlab Distribution of malicious Korean HWP files with lawsuit-related content - KONNI organization

https://asec.ahnlab.com/1277

Thumbnail for 소송 관련 내용의 악성 한글 HWP 파일 유포 - 코니(KONNI) 조직

AhnLab reported a malicious HWP file tied to the Konni cluster and the Operation MoneyHolic activity set. The lure was presented as a legal response document for a private hospital lawsuit and contained a malicious PostScript object. Shellcode analysis led AhnLab to assess that the file was distributed by Konni or an Operation MoneyHolic-related actor. The report provides a file hash and execution-flow context useful for detecting HWP/PostScript delivery chains associated with Korean-language APT activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f5339239a6bcda0afe61e6ef8bfafe5… 2019-12-12 2019-12-12
HASH bbde7c694faf6b450adbfc8efe88a41a 2019-12-12 2019-12-12

Related Actors

Related Reports

« Back