암호화폐 내용의 Konni APT 캠페인과 '오퍼레이션 헌터 아도니스'
2019-01-02 • ESTSecurity • Cryptocurrency-related Konni APT campaign and ‘Operation Hunter Adonis' •
ESRC links the Konni campaign to lure documents that historically used North Korea-related themes and, in late 2018, also impersonated policy material and cryptocurrency wallet-related documents. The documented infection chain uses malicious Word macros that fetch Base64-encoded text files, decode a CAB payload with certutil, run install.bat, and persist Word.exe via the HKCU Run key as svchost. Word.exe decodes winnet.ini and connects to 103.249.31.159:7777, checks for the fxftest string, and can receive additional commands, including installation of remote-control malware such as TeamViewer-like modules. The report notes overlap with techniques seen in Kimsuky activity and raises false-flag considerations, while listing artifacts such as filer2.1apps.com, Word.exe, winnet.ini, ADONIS account traces, and multiple PDB paths useful for tracking related Konni variants.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 103.249.31.159 | 2018-12-20 | 2019-08-29 |
| DOMAIN | filer2.1apps.com | 2018-12-20 | 2019-06-10 |
| URL | http://filer2.1apps.com/3.txt | 2019-01-02 | 2019-01-02 |
| URL | http://read.pudn.com/downloads6… | 2019-01-02 | 2019-01-02 |
| URL | http://filer2.1apps.com/2.txt | 2019-01-02 | 2019-01-02 |