Analyzing spear-phishing campaign by Konni APT

2025-03-27 Priya Patel

https://prii308.github.io/Analyzing-spear-phishing-campaign-by-Konni-APT/

Thumbnail for Analyzing spear-phishing campaign by Konni APT

A suspected Konni APT spear-phishing campaign used a malicious LNK file that launches mshta and extracts an embedded PowerShell script into C:\ProgramData. The script connects to 64.20.59.148 on ports 8855 and 6699, downloads a ZIP from Dropbox, and drops obfuscated JavaScript and PowerShell components. Persistence is established through a scheduled task disguised as a Microsoft Edge update task and a Run key under HKCU. The later PowerShell stage uses Google Drive API authentication to upload execution logs, search for operator-provided files, and retrieve additional content, showing a multi-stage data theft and command-delivery workflow.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 64.20.59.148 2025-02-26 2025-05-13
HASH 6fb3dfe451b37b0304a42e62759bf36… 2025-03-27 2025-04-10
HASH ec78b61a5f54805bbdffd69d57ce76d… 2025-03-27 2025-03-27
HASH 1a61340179c811b17c332452cfd1d72… 2025-03-27 2025-03-27
HASH a1376496406895a00d9009b36a6e107… 2025-03-27 2025-03-27
HASH 9ce42177bafe552495b8329726bb4ac… 2025-03-27 2025-03-27
URL https://www.dropbox.com/scl/fi/… 2025-03-27 2025-03-27
DOMAIN 65054017293-3uhs23bl4ffvlbutcle… 2025-03-27 2025-03-27

Related Actors

Related Reports

« Back