Analysis of the Spear-Phishing and KakaoTalk-Linked Threat Campaign by the Konni Group
2026-03-15 • Genians •
https://www.genians.co.kr/en/blog/threat_intelligence/kakaotalk
Genians Security Center analyzed a Konni APT campaign that used North Korea-themed spear-phishing to gain initial access. The lure impersonated a notice appointing the recipient as a North Korean human-rights lecturer and delivered an archive containing a malicious LNK shortcut disguised as a normal document. When executed, the LNK launched cmd.exe and 32-bit PowerShell, extracted and ran an embedded decoy PDF, downloaded additional payloads from drfeysal[.]com, and established persistence through scheduled tasks, startup entries, or process masquerading. The actor remained concealed on the endpoint while collecting internal documents, account information, and system environment data, then abused the victim's KakaoTalk PC session to send malicious files to selected contacts. The campaign is notable for combining spear-phishing, long-term persistence, information theft, and account-based messenger propagation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7dc50e8af0070e544bff5299405cd3b9 | 2026-03-15 | 2026-03-15 |
| HASH | 461ade40b800ae80a40985594e1ac236 | 2026-03-15 | 2026-03-15 |
| HASH | 3288c284561055044c489567fd630ac2 | 2026-03-15 | 2026-03-15 |
| HASH | 2e1b0ac49313873a0e0b982c591a5264 | 2026-03-15 | 2026-03-15 |
| HASH | 148405ff05bf15a6a053e4e7c1795d40 | 2026-03-15 | 2026-03-15 |
| HASH | 01022facb38cf60b052e65a682f4a127 | 2026-03-15 | 2026-03-15 |
| DOMAIN | drfeysal.com | 2026-03-15 | 2026-03-15 |
| IPv4 | 96.62.214.5 | 2026-03-15 | 2026-03-15 |
| IPv4 | 157.180.88.26 | 2026-03-15 | 2026-03-15 |
| IPv4 | 185.21.14.249 | 2026-03-15 | 2026-03-15 |
| IPv4 | 178.16.54.208 | 2026-03-15 | 2026-03-15 |
| HASH | 61f65bd593ea0e52ac0dfdc6bc9cd73a | 2024-07-31 | 2026-03-15 |