Analysis of the KONNI's LINKON Malware
2025-02-14 • S2W •
S2W TALON analyzed LINKON malware associated with the North Korea-backed KONNI group, delivered as an LNK file disguised as a South Korean Financial Services Commission virtual-asset inspection document. The January 2025 sample used PowerShell to drop and execute a decoy document alongside embedded malicious files, hiding execution from the user. KONNVBS and KONNBAT scripts maintained persistence through Windows Task Scheduler or downloaded additional components from a hardcoded attacker-controlled server. The lure theme suggests targeting of virtual asset businesses after the December 2024 Anti-Money Laundering Inspection Trustee Council meeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e37c8f6aba686aab3d7ecedbd1d0ef43 | 2025-02-14 | 2026-01-14 |
| HASH | 5a8ecafbd5809000334bf5b940a497d… | 2025-02-14 | 2025-02-20 |