A Deep Dive Into a Multi-Stage Malware Campaign Potentially Linked to DPRK’s Konni Group

2025-04-23 navneet

https://muff-in.github.io/blog/Malware-Campaign-Potentially-Linked-to-DPRK-Konni-Group/

Thumbnail for A Deep Dive Into a Multi-Stage Malware Campaign Potentially Linked to DPRK’s Konni Group

A suspicious ZIP archive delivered a Korean-named LNK file disguised as a PDF proposal, and the source assesses its TTPs as similar to prior operations linked to DPRK's Konni group. The infection chain uses a double-extension LNK with a PDF icon to run obfuscated PowerShell, carve embedded content from the LNK, decrypt payloads with XOR, display a decoy proposal PDF, and unpack a CAB into the public Documents directory. The decoy includes a KakaoTalk Open Chat link themed around Naver and Coupang online-store marketing, suggesting social engineering aimed at Korean-speaking users. Later stages run start.vbs and batch files for persistence via HKCU Run, download a password-protected ZIP from ausbildungsbuddy.de, and continue execution through additional scripts. The campaign is notable for combining Korean-language lure material, multi-stage script execution, cleanup, and potentially compromised infrastructure in a flow the author links cautiously to Konni-style DPRK activity.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://ausbildungsbuddy.de/mod… 2025-04-23 2025-05-19
URL https://ausbildungsbuddy.de/mod… 2025-04-23 2025-05-19
URL https://ausbildungsbuddy.de/mod… 2025-04-23 2025-05-19
DOMAIN ausbildungsbuddy.de 2025-04-23 2025-05-19
HASH 627ee714b1e4f5bd692061e1c297831… 2025-04-23 2025-04-23
URL https://ausbildungsbuddy.de/ 2025-04-23 2025-04-23
URL https://jmarketing.agency/ 2025-04-23 2025-04-23
DOMAIN jmarketing.agency 2025-04-23 2025-04-23
DOMAIN fromausbildungsbuddy.de 2025-04-23 2025-04-23

Related Actors

Related Reports

« Back