Amenințări avansate: KONNI Campanie curentă de phishing

2025-03-19 RODNSC

https://dnsc.ro/citeste/amenintari-avansate-konni-campanie-curent-de-phishing

DNSC reports an active phishing campaign that it assesses is very likely linked to Konni, a North Korea-associated group often discussed alongside APT37 and Kimsuky. The infection chain uses malicious Windows LNK email attachments that run hidden PowerShell, open a decoy document, and install AsyncRAT on the victim system. Payload delivery and later-stage activity rely on both proxy command-and-control servers and trusted cloud services including Dropbox and Google Drive, with recent samples passing C2 details as runtime parameters rather than hard-coding them. The report lists multiple hashes, C2 IPs, cloud URLs, and MITRE techniques tied to scripting, malicious links, scheduled tasks, obfuscation, web services, and cloud-service exfiltration, making the activity relevant for tracking DPRK-linked espionage tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 74.50.94.175 2025-03-12 2025-05-19
URL https://www.dropbox.com/scl/fi/… 2025-03-19 2025-03-19
IPv4 162.125.65.19 2025-03-19 2025-03-19
IPv4 162.125.65.18 2025-03-19 2025-03-19
IPv4 162.125.65.15 2025-03-19 2025-03-19
HASH 694af547d321771e69c48cf3c04411f… 2025-03-12 2025-03-19
HASH 9af27198deefa87bb1d3868abb295f0… 2025-03-12 2025-03-19
HASH 47abd1682a88f7aadd3fe57583a7edb… 2025-03-12 2025-03-19
HASH 7a21d0e9793a4f115d395c6e99927d5… 2025-03-12 2025-03-19
HASH 5967513540ad610ddbbc124f2437cf5… 2025-03-12 2025-03-19
HASH 68621690299e676b7562aca350a4ab8… 2025-03-12 2025-03-19
HASH 811d221a1340e64aa1736d9d4e8f808… 2025-03-12 2025-03-19
URL https://lh3.googleusercontent.c… 2025-03-12 2025-03-19
IPv4 74.50.94.47 2025-03-12 2025-03-19
HASH 268640934dd1f0cfe3a365322185885… 2025-02-21 2025-03-19
IPv4 206.206.127.152 2024-10-08 2025-03-19

Related Actors

Related Reports

« Back