Analysis of Konni RAT: Stealth, Persistence, and Anti-Analysis Techniques

2025-03-28 Cyfirma

https://www.cyfirma.com/research/analysis-of-konni-rat-stealth-persistence-and-anti-analysis-techniques/

Thumbnail for Analysis of Konni RAT: Stealth, Persistence, and Anti-Analysis Techniques

In February 2024, it was embedded in software used by the Russian Ministry of Foreign Affairs to target sensitive systems, while in November 2023, phishing attacks employed malicious documents to deploy the malware, enabling attackers to exfiltrate data and execute remote commands. The malware is known for its sophisticated capabilities, including data exfiltration, command execution, persistence through UAC bypass and registry modifications, and encrypted communication with its command-and-control (C2) servers. The malware exploits default features of Windows OS, such as Windows Explorer’s file extension hiding and the 260-character limit in LNK files, enabling it to execute commands undetected. Recent campaigns have showcased Konni RAT’s evolving tactics, such as embedding itself within backdoored software installers or leveraging malicious macro-enabled Word documents to gain access.

Indicators of Compromise

Type Value First Seen Last Seen
YARA Konni_RAT 2025-03-28 2025-03-28
HASH 76ee4da0af1921b820cc0913b4011bb… 2025-03-28 2025-03-28
HASH a8b0f9717bc16d48e55be9588650017… 2025-03-28 2025-03-28
HASH cae6a87fd9ab544e5ccceb38f35c201e 2025-03-28 2025-03-28
HASH 474978a976de1c869385d37ae422b17… 2025-03-28 2025-03-28
HASH c348e945e1f6123bd054277d16a39da… 2025-03-28 2025-03-28
HASH 4c53e24db4b7858fd9d17de2bfc3d73… 2025-03-28 2025-03-28
HASH 61ce43ea1c2ddafb23ee8ee083417fd… 2025-03-28 2025-03-28
HASH ee8e8471fbe1b7fc85508e549444893… 2025-03-28 2025-03-28
HASH f1b4eb84e77e39803a0463b49b66600… 2025-03-28 2025-03-28
HASH a19b9eb292395e0d84c4a1a8eb5c88a… 2025-03-28 2025-03-28
HASH e3c3981f65663c9923da9ca28c20951… 2025-03-28 2025-03-28
URL https://www.roofcolor.com/wp-in… 2025-03-28 2025-03-28
URL https://www.acschoolcatering.co… 2025-03-28 2025-03-28
URL http://www.roofcolor.com/wp-inc… 2025-03-28 2025-03-28
URL https://www.roofcolor.com/wp-in… 2025-03-28 2025-03-28
URL https://www.roofcolor.com/wp-in… 2025-03-28 2025-03-28
URL https://www.acschoolcatering.co… 2025-03-28 2025-03-28
HASH a2785ec65622217be80174b887b1eb06 2025-03-07 2025-03-28
HASH b81513f0f8d3db382bb8f931bf2b7a0… 2025-03-07 2025-03-28
URL http://www.roofcolor.com/wp-inc… 2025-03-07 2025-03-28
DOMAIN roofcolor.com 2025-03-07 2025-03-28
DOMAIN acschoolcatering.com 2025-03-07 2025-03-28

Related Actors

Related Reports

« Back