주적 북한 해킹 단체 코니(Konni)에서 제작한 악성코드-자금출처명세서.lnk(2025.5.28)

2025-07-21 Sakai Malware Created by North Korean Hostile Hacking Group Konni - Statement of Source of Funds.lnk (2025.5.28)

https://wezard4u.tistory.com/429544

Thumbnail for 주적 북한 해킹 단체 코니(Konni)에서 제작한 악성코드-자금출처명세서.lnk(2025.5.28)

The source analyzes a Konni-attributed LNK malware sample disguised as a Hangul document named like a funds source statement. Its embedded PowerShell searches for a specifically sized .lnk file, extracts XOR-decoded payload data from offsets in that file, writes a CAB file under the Public documents path, expands it, and launches a VBS script. Follow-on batch scripts enumerate the user's Downloads, Documents, Desktop, and system information into text files for collection. The stealer logic encrypts local files with an RC4 implementation using a time-derived key, Base64-encodes the result, and POSTs it with a browser-like user agent. The exfiltration endpoint is hxxps://24hrkpop(.)com/wp-includes/js/src/lib/upload(.)php, and the source says the Korean K-pop website was compromised to support malware distribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ba708acd2ea044fd8076dfd1bb540e77 2025-07-21 2025-07-21
HASH 066ef37379b12dcd9e1524b936d65c0… 2025-07-21 2025-07-21
HASH d5b59f06c2505cb28d1e7e52138b40e… 2025-07-21 2025-07-21
URL https://24hrkpop.com/wp-include… 2025-07-21 2025-07-21
DOMAIN 24hrkpop.com 2025-07-21 2025-07-21

Related Actors

Related Reports

« Back