Analyzing spear-phishing campaign by Konni APT
2025-03-27 • Priya Patel •
https://prii308.github.io/Analyzing-spear-phishing-campaign-by-Konni-APT/
A suspected Konni APT spear-phishing campaign used a malicious LNK file that launches mshta and extracts an embedded PowerShell script into C:\ProgramData. The script connects to 64.20.59.148 on ports 8855 and 6699, downloads a ZIP from Dropbox, and drops obfuscated JavaScript and PowerShell components. Persistence is established through a scheduled task disguised as a Microsoft Edge update task and a Run key under HKCU. The later PowerShell stage uses Google Drive API authentication to upload execution logs, search for operator-provided files, and retrieve additional content, showing a multi-stage data theft and command-delivery workflow.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 64.20.59.148 | 2025-02-26 | 2025-05-13 |
| HASH | 6fb3dfe451b37b0304a42e62759bf36… | 2025-03-27 | 2025-04-10 |
| HASH | ec78b61a5f54805bbdffd69d57ce76d… | 2025-03-27 | 2025-03-27 |
| HASH | 1a61340179c811b17c332452cfd1d72… | 2025-03-27 | 2025-03-27 |
| HASH | a1376496406895a00d9009b36a6e107… | 2025-03-27 | 2025-03-27 |
| HASH | 9ce42177bafe552495b8329726bb4ac… | 2025-03-27 | 2025-03-27 |
| URL | https://www.dropbox.com/scl/fi/… | 2025-03-27 | 2025-03-27 |
| DOMAIN | 65054017293-3uhs23bl4ffvlbutcle… | 2025-03-27 | 2025-03-27 |