코니(Konni) APT 조직, 러시아 문서로 위장한 공격 등장

2019-08-19 ESTSecurity Konni APT organization launches attack disguised as Russian document

https://blog.alyac.co.kr/2474

Thumbnail for 코니(Konni) APT 조직, 러시아 문서로 위장한 공격 등장

ESTsecurity analyzed a Konni-series malicious Word document using a Russian filename about the Korean Peninsula and U.S.–DPRK dialogue, while internal code-page artifacts showed Korean-language build characteristics. The document contains VBA macros and an ObjectPool payload that launches certutil to download and decode Base64-staged files from handicap.eu5[.]org, then loads 32-bit or 64-bit DLL payloads and retrieves attacker-controlled configuration. ESRC links the tradecraft to earlier Konni activity, including a January 2019 Russian-language decoy document, because the macro structure, ObjectPool-hidden C2 logic and staged CAB/DLL delivery pattern closely match prior samples. The report highlights C2 and payload infrastructure such as handicap.eu5[.]org and clean.1apps[.]com, plus MD5 hashes for the analyzed documents and payloads, as evidence for defenders tracking Konni operations.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN handicap.eu5.org 2019-08-19 2020-01-23
URL http://handicap.eu5.org/1.txt 2019-08-19 2020-01-05
DOMAIN clean.1apps.com 2019-05-24 2020-01-05
DOMAIN ftpupload.net 2019-05-24 2020-01-05
DOMAIN 1apps.com 2018-11-29 2020-01-05
HASH c313a3aca90a614dd0ff6ce28c6ae2f0 2019-08-19 2019-08-19
HASH 660a640e702606341ab0d42724380322 2019-08-19 2019-08-19
URL http://clean.1apps.com/3.txt 2019-08-19 2019-08-19
URL http://handicap.eu5.org/2.txt 2019-08-19 2019-08-19
URL http://clean.1apps.com/2.txt 2019-08-19 2019-08-19
URL http://handicap.eu5.org/4.txt 2019-08-19 2019-08-19
URL http://handicap.eu5.org/3.txt 2019-08-19 2019-08-19
HASH 68b080cdc748e9357e75a65fba30eaa7 2019-05-24 2019-08-19
URL http://clean.1apps.com/4.txt 2019-05-24 2019-08-19
URL http://clean.1apps.com/1.txt 2019-05-24 2019-08-19

Related Actors

Related Reports

« Back