A Deep Dive Into a Multi-Stage Malware Campaign Potentially Linked to DPRK’s Konni Group
2025-04-23 • navneet •
https://muff-in.github.io/blog/Malware-Campaign-Potentially-Linked-to-DPRK-Konni-Group/
A suspicious ZIP archive delivered a Korean-named LNK file disguised as a PDF proposal, and the source assesses its TTPs as similar to prior operations linked to DPRK's Konni group. The infection chain uses a double-extension LNK with a PDF icon to run obfuscated PowerShell, carve embedded content from the LNK, decrypt payloads with XOR, display a decoy proposal PDF, and unpack a CAB into the public Documents directory. The decoy includes a KakaoTalk Open Chat link themed around Naver and Coupang online-store marketing, suggesting social engineering aimed at Korean-speaking users. Later stages run start.vbs and batch files for persistence via HKCU Run, download a password-protected ZIP from ausbildungsbuddy.de, and continue execution through additional scripts. The campaign is notable for combining Korean-language lure material, multi-stage script execution, cleanup, and potentially compromised infrastructure in a flow the author links cautiously to Konni-style DPRK activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | https://ausbildungsbuddy.de/mod… | 2025-04-23 | 2025-05-19 |
| URL | https://ausbildungsbuddy.de/mod… | 2025-04-23 | 2025-05-19 |
| URL | https://ausbildungsbuddy.de/mod… | 2025-04-23 | 2025-05-19 |
| DOMAIN | ausbildungsbuddy.de | 2025-04-23 | 2025-05-19 |
| HASH | 627ee714b1e4f5bd692061e1c297831… | 2025-04-23 | 2025-04-23 |
| URL | https://ausbildungsbuddy.de/ | 2025-04-23 | 2025-04-23 |
| URL | https://jmarketing.agency/ | 2025-04-23 | 2025-04-23 |
| DOMAIN | jmarketing.agency | 2025-04-23 | 2025-04-23 |
| DOMAIN | fromausbildungsbuddy.de | 2025-04-23 | 2025-04-23 |