한국어 구사 Konni 조직, 블루 스카이 작전 'Amadey' 러시아 봇넷 활용

2019-05-16 ESTSecurity Korean-Speaking Konni Gang Leverages Russian Botnet in Operation Blue Sky 'Amadey'

https://blog.alyac.co.kr/2308

Thumbnail for 한국어 구사 Konni 조직, 블루 스카이 작전 'Amadey' 러시아 봇넷 활용

ESRC ties Operation Blue Sky to a Korean-speaking Konni cluster after repeated malicious DOC variants reused the “BlueSky” author account and cryptocurrency-themed decoys. The documents urged macro execution, then contacted spoofed portal-like or 1apps-hosted C2 paths such as mail.naver-download.com, alabamaok0515.1apps.com, fighiting1013.org, and tgbabcrfv.1apps.com to retrieve staged scripts and payloads. The chain copied certutil.exe as ct.exe, decoded Base64 data into setup.cab, installed executables such as picture.exe or victory.exe, and set Run-key persistence. One stage attempted to download sp.exe and connect to an AMADEY panel at charley-online.com/back/2019/index.php, showing Konni’s Blue Sky activity incorporating a publicly available Russian botnet component.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN 1apps.com 2018-11-29 2020-01-05
DOMAIN alabamaok0515.1apps.com 2019-05-16 2019-08-29
DOMAIN fighiting1013.org 2019-05-16 2019-08-29
DOMAIN mail.naver-download.com 2019-05-16 2019-08-24
HASH 0eb6090397c74327cd4d47819f724953 2018-12-20 2019-06-10
HASH 2bfbf8ce47585aa86b1ab90ff109fd57 2018-12-20 2019-06-10
DOMAIN filer2.1apps.com 2018-12-20 2019-06-10
DOMAIN filer1.1apps.com 2018-11-29 2019-06-10
URL http://fighiting1013.org/2/sp.e… 2019-05-16 2019-05-24
DOMAIN tgbabcrfv.1apps.com 2019-05-16 2019-05-24
DOMAIN charley-online.com 2019-05-16 2019-05-24
URL http://alabamaok0515.1apps.com/… 2019-05-16 2019-05-16
URL http://fighiting1013.org/2/ 2019-05-16 2019-05-16
URL http://charley-online.com/back/… 2019-05-16 2019-05-16
URL http://mail.naver-download.com/… 2019-05-16 2019-05-16
URL http://tgbabcrfv.1apps.com/ 2019-05-16 2019-05-16
IPv4 81.90.188.76 2019-05-16 2019-05-16

Related Actors

Related Reports

« Back