한국어 구사 Konni 조직, 블루 스카이 작전 'Amadey' 러시아 봇넷 활용
2019-05-16 • ESTSecurity • Korean-Speaking Konni Gang Leverages Russian Botnet in Operation Blue Sky 'Amadey' •
ESRC ties Operation Blue Sky to a Korean-speaking Konni cluster after repeated malicious DOC variants reused the “BlueSky” author account and cryptocurrency-themed decoys. The documents urged macro execution, then contacted spoofed portal-like or 1apps-hosted C2 paths such as mail.naver-download.com, alabamaok0515.1apps.com, fighiting1013.org, and tgbabcrfv.1apps.com to retrieve staged scripts and payloads. The chain copied certutil.exe as ct.exe, decoded Base64 data into setup.cab, installed executables such as picture.exe or victory.exe, and set Run-key persistence. One stage attempted to download sp.exe and connect to an AMADEY panel at charley-online.com/back/2019/index.php, showing Konni’s Blue Sky activity incorporating a publicly available Russian botnet component.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | 1apps.com | 2018-11-29 | 2020-01-05 |
| DOMAIN | alabamaok0515.1apps.com | 2019-05-16 | 2019-08-29 |
| DOMAIN | fighiting1013.org | 2019-05-16 | 2019-08-29 |
| DOMAIN | mail.naver-download.com | 2019-05-16 | 2019-08-24 |
| HASH | 0eb6090397c74327cd4d47819f724953 | 2018-12-20 | 2019-06-10 |
| HASH | 2bfbf8ce47585aa86b1ab90ff109fd57 | 2018-12-20 | 2019-06-10 |
| DOMAIN | filer2.1apps.com | 2018-12-20 | 2019-06-10 |
| DOMAIN | filer1.1apps.com | 2018-11-29 | 2019-06-10 |
| URL | http://fighiting1013.org/2/sp.e… | 2019-05-16 | 2019-05-24 |
| DOMAIN | tgbabcrfv.1apps.com | 2019-05-16 | 2019-05-24 |
| DOMAIN | charley-online.com | 2019-05-16 | 2019-05-24 |
| URL | http://alabamaok0515.1apps.com/… | 2019-05-16 | 2019-05-16 |
| URL | http://fighiting1013.org/2/ | 2019-05-16 | 2019-05-16 |
| URL | http://charley-online.com/back/… | 2019-05-16 | 2019-05-16 |
| URL | http://mail.naver-download.com/… | 2019-05-16 | 2019-05-16 |
| URL | http://tgbabcrfv.1apps.com/ | 2019-05-16 | 2019-05-16 |
| IPv4 | 81.90.188.76 | 2019-05-16 | 2019-05-16 |