Analysis of the recent offensive operations conducted by North Korean APT groups

2023-09-13 Knownsec

https://paper.seebug.org/3031/

Thumbnail for Analysis of the recent offensive operations conducted by North Korean APT groups

Knownsec 404 observed a sharp increase in North Korean APT activity against South Korea during August 2023, with attack timing overlapping the Ulchi Freedom Shield military exercise. The team collected more than 200 deduplicated samples, including more than 80 during the exercise period, and assessed that APT37 accounted for over 90% of the captured activity while Konni also became active later in the month. Initial delivery relied mainly on LNK and CHM droppers, with APT37 using oversized LNK files and Chinotto variants, and Konni using phishing lures such as salary statements, Ministry of Unification-themed documents, and security email password themes. The Konni chain used embedded CHM scripts, VBS and BAT stages, bitsadmin and certutil, registry Run persistence, system and desktop-file collection, and C2 download/upload activity including chainilnk.site. The activity matters because it shows high-volume, intelligence-gathering-focused DPRK operations against South Korean targets with evolving but reusable script-based tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 778e46f8f3641a92d34da68dffc168f… 2023-09-12 2024-08-22
HASH d245f208d2a682f4d2c4464557973bf… 2023-09-12 2024-05-20
HASH dd85c8400fb30e4d02f0159aab3c3db… 2023-09-01 2023-11-24
HASH b3653c1d66f7878c2c5b60506bfe6fb… 2023-09-12 2023-09-13
HASH 9fd5094447ff48e7ec032ced663717c… 2023-09-12 2023-09-13
HASH 6a6f7bdca0423b8702c1803bf5593e2… 2023-09-12 2023-09-13
HASH be568aad2e29b25609358b7793a36eb… 2023-09-12 2023-09-13
HASH f9171a375f765eae7a0babe94acaa08… 2023-09-12 2023-09-13
HASH 440ca9963b73653615de02e44b2ccd1… 2023-09-12 2023-09-13
HASH f4897180b6d70b8134ed0a433af33ae… 2023-09-12 2023-09-13
HASH 87d60ea4650c18a1629892b26e22c97… 2023-09-12 2023-09-13
HASH 151bfb656ce44249960c7aee094884c… 2023-09-12 2023-09-13
HASH cabdc51411d452e30e6fd6786a95752… 2023-09-12 2023-09-13
URL https://chainilnk.site/customer… 2023-09-12 2023-09-13
DOMAIN chainilnk.site 2023-09-12 2023-09-13
HASH b31b89e646de6e9c5cbe21798e0157f… 2023-09-07 2023-09-13
HASH 01e7405ddd5545ffb4a57040acc4b6f… 2023-08-25 2023-09-13
HASH a1f6ae788bf3f9ae17893f3b12d557f… 2023-08-25 2023-09-13
HASH 012063e0b7b4f7f3ce50574797112f9… 2023-08-25 2023-09-13
HASH f5e46e18facc6f8fde6658b96dcd379… 2023-08-25 2023-09-13
HASH 578689cb4b06c4d3f1850e4379c4b31… 2023-08-25 2023-09-13

Related Actors

Related Reports

« Back