코니(Konni) APT 조직, HWP 취약점을 이용한 'Coin Plan' 작전 감행

2019-10-01 ESTSecurity Konni APT organization conducts ‘Coin Plan' operation using HWP vulnerability

https://blog.alyac.co.kr/2543

Thumbnail for 코니(Konni) APT 조직, HWP 취약점을 이용한 'Coin Plan' 작전 감행

ESRC reported Operation Coin Plan, a Konni campaign with strong Kimsuky links that used a malicious HWP document named as a marketing plan for cryptocurrency mining. The HWP file embedded BIN0001.PS PostScript, decoded shellcode with a 16-byte XOR key, and attempted to contact attacker-controlled C2 if the exploit succeeded. The lure content centered on cryptocurrency mining, aligning with the group’s recent use of coin-related themes. The report is relevant for defenders tracking HWP exploit chains, Konni/Kimsuky overlap, and crypto-themed spear-phishing operations.

Related Actors

Related Reports

« Back