Amenințări avansate: KONNI Campanie curentă de phishing
2025-03-19 • RODNSC •
https://dnsc.ro/citeste/amenintari-avansate-konni-campanie-curent-de-phishing
DNSC reports an active phishing campaign that it assesses is very likely linked to Konni, a North Korea-associated group often discussed alongside APT37 and Kimsuky. The infection chain uses malicious Windows LNK email attachments that run hidden PowerShell, open a decoy document, and install AsyncRAT on the victim system. Payload delivery and later-stage activity rely on both proxy command-and-control servers and trusted cloud services including Dropbox and Google Drive, with recent samples passing C2 details as runtime parameters rather than hard-coding them. The report lists multiple hashes, C2 IPs, cloud URLs, and MITRE techniques tied to scripting, malicious links, scheduled tasks, obfuscation, web services, and cloud-service exfiltration, making the activity relevant for tracking DPRK-linked espionage tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 74.50.94.175 | 2025-03-12 | 2025-05-19 |
| URL | https://www.dropbox.com/scl/fi/… | 2025-03-19 | 2025-03-19 |
| IPv4 | 162.125.65.19 | 2025-03-19 | 2025-03-19 |
| IPv4 | 162.125.65.18 | 2025-03-19 | 2025-03-19 |
| IPv4 | 162.125.65.15 | 2025-03-19 | 2025-03-19 |
| HASH | 694af547d321771e69c48cf3c04411f… | 2025-03-12 | 2025-03-19 |
| HASH | 9af27198deefa87bb1d3868abb295f0… | 2025-03-12 | 2025-03-19 |
| HASH | 47abd1682a88f7aadd3fe57583a7edb… | 2025-03-12 | 2025-03-19 |
| HASH | 7a21d0e9793a4f115d395c6e99927d5… | 2025-03-12 | 2025-03-19 |
| HASH | 5967513540ad610ddbbc124f2437cf5… | 2025-03-12 | 2025-03-19 |
| HASH | 68621690299e676b7562aca350a4ab8… | 2025-03-12 | 2025-03-19 |
| HASH | 811d221a1340e64aa1736d9d4e8f808… | 2025-03-12 | 2025-03-19 |
| URL | https://lh3.googleusercontent.c… | 2025-03-12 | 2025-03-19 |
| IPv4 | 74.50.94.47 | 2025-03-12 | 2025-03-19 |
| HASH | 268640934dd1f0cfe3a365322185885… | 2025-02-21 | 2025-03-19 |
| IPv4 | 206.206.127.152 | 2024-10-08 | 2025-03-19 |