Analysis of the KONNI's LINKON Malware

2025-02-14 S2W

https://s2w.inc/en/resource/detail/758

Thumbnail for Analysis of the KONNI's LINKON Malware

S2W TALON analyzed LINKON malware associated with the North Korea-backed KONNI group, delivered as an LNK file disguised as a South Korean Financial Services Commission virtual-asset inspection document. The January 2025 sample used PowerShell to drop and execute a decoy document alongside embedded malicious files, hiding execution from the user. KONNVBS and KONNBAT scripts maintained persistence through Windows Task Scheduler or downloaded additional components from a hardcoded attacker-controlled server. The lure theme suggests targeting of virtual asset businesses after the December 2024 Anti-Money Laundering Inspection Trustee Council meeting.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e37c8f6aba686aab3d7ecedbd1d0ef43 2025-02-14 2026-01-14
HASH 5a8ecafbd5809000334bf5b940a497d… 2025-02-14 2025-02-20

Related Actors

Related Reports

« Back