Analysis of the Spear-Phishing and KakaoTalk-Linked Threat Campaign by the Konni Group

2026-03-15 Genians

https://www.genians.co.kr/en/blog/threat_intelligence/kakaotalk

Thumbnail for Analysis of the Spear-Phishing and KakaoTalk-Linked Threat Campaign by the Konni Group

Genians Security Center analyzed a Konni APT campaign that used North Korea-themed spear-phishing to gain initial access. The lure impersonated a notice appointing the recipient as a North Korean human-rights lecturer and delivered an archive containing a malicious LNK shortcut disguised as a normal document. When executed, the LNK launched cmd.exe and 32-bit PowerShell, extracted and ran an embedded decoy PDF, downloaded additional payloads from drfeysal[.]com, and established persistence through scheduled tasks, startup entries, or process masquerading. The actor remained concealed on the endpoint while collecting internal documents, account information, and system environment data, then abused the victim's KakaoTalk PC session to send malicious files to selected contacts. The campaign is notable for combining spear-phishing, long-term persistence, information theft, and account-based messenger propagation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7dc50e8af0070e544bff5299405cd3b9 2026-03-15 2026-03-15
HASH 461ade40b800ae80a40985594e1ac236 2026-03-15 2026-03-15
HASH 3288c284561055044c489567fd630ac2 2026-03-15 2026-03-15
HASH 2e1b0ac49313873a0e0b982c591a5264 2026-03-15 2026-03-15
HASH 148405ff05bf15a6a053e4e7c1795d40 2026-03-15 2026-03-15
HASH 01022facb38cf60b052e65a682f4a127 2026-03-15 2026-03-15
DOMAIN drfeysal.com 2026-03-15 2026-03-15
IPv4 96.62.214.5 2026-03-15 2026-03-15
IPv4 157.180.88.26 2026-03-15 2026-03-15
IPv4 185.21.14.249 2026-03-15 2026-03-15
IPv4 178.16.54.208 2026-03-15 2026-03-15
HASH 61f65bd593ea0e52ac0dfdc6bc9cd73a 2024-07-31 2026-03-15

Related Actors

Related Reports

« Back