Konni의 최신 AsyncRAT 공격: LNK 파일을 활용한 감염 기법

2025-03-12 ENKI Konni's Latest AsyncRAT Attack: Infection Technique Using LNK Files

https://www.enki.co.kr/media-center/blog/konni-s-asyncrat-attack-lnk-based-infection

Thumbnail for Konni의 최신 AsyncRAT 공격: LNK 파일을 활용한 감염 기법

ENKI links a set of VirusTotal-hunted LNK samples to Konni activity associated with North Korean operations and describes a multi-stage infection chain ending in an AsyncRAT variant. The LNK files extract and execute obfuscated PowerShell from embedded data, then retrieve additional JavaScript and PowerShell payloads through Dropbox, C2 servers, and Google Drive. The chain establishes persistence through scheduled tasks and HKCU Run keys, creates infection logs in an attacker-controlled Google Drive, and appears to use file polling or manual staging to deliver follow-on payloads. The final AsyncRAT resembles previously reported Konni-linked AsyncRAT code but receives its C2 IP and port as runtime arguments rather than relying only on hardcoded configuration, with 206.206.127[.]152 observed in the analyzed activity.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN 71532697854-ef1nlsl4cjn4scm57ds… 2025-03-12 2025-05-19
DOMAIN 159263970130-1gil63rpicrhtbo4he… 2025-03-12 2025-05-19
IPv4 74.50.94.175 2025-03-12 2025-05-19
HASH 694af547d321771e69c48cf3c04411f… 2025-03-12 2025-03-19
HASH 9af27198deefa87bb1d3868abb295f0… 2025-03-12 2025-03-19
HASH 47abd1682a88f7aadd3fe57583a7edb… 2025-03-12 2025-03-19
HASH 7a21d0e9793a4f115d395c6e99927d5… 2025-03-12 2025-03-19
HASH 5967513540ad610ddbbc124f2437cf5… 2025-03-12 2025-03-19
HASH 68621690299e676b7562aca350a4ab8… 2025-03-12 2025-03-19
HASH 811d221a1340e64aa1736d9d4e8f808… 2025-03-12 2025-03-19
URL https://lh3.googleusercontent.c… 2025-03-12 2025-03-19
IPv4 74.50.94.47 2025-03-12 2025-03-19
HASH 268640934dd1f0cfe3a365322185885… 2025-02-21 2025-03-19
IPv4 206.206.127.152 2024-10-08 2025-03-19
HASH 2ad3120e1b03317d8d588d0cc097cc4… 2025-03-12 2025-03-12
HASH 52b8e4da732d06000e29d7609668021… 2025-03-12 2025-03-12
HASH e6e3a8fb352641bb5b6f6db1479490d… 2025-03-12 2025-03-12
HASH 11afe5cc28666c39d3dc3e9d51f780e… 2025-03-12 2025-03-12
HASH f4c4f68f8b27279b00b718b02392d5d… 2025-03-12 2025-03-12
HASH dfeec1052063d6dc69cc6d23ca0cd26… 2025-03-12 2025-03-12
HASH 9c9df2d90602c915005811aabf44465… 2025-03-12 2025-03-12
HASH 11ac6151182db3b41f9022b4e4b8a38… 2025-03-12 2025-03-12
HASH f3aee5924279dd1883efbb04c891663… 2025-03-12 2025-03-12
HASH aacb5aca178f6444a82bca1febb282a… 2025-03-12 2025-03-12
HASH ba52ab256079f80fdf9c47bf5fc215f… 2025-03-12 2025-03-12
EMAIL [email protected] 2025-03-12 2025-03-12
EMAIL [email protected] 2025-03-12 2025-03-12
EMAIL [email protected] 2025-03-12 2025-03-12
URL https://lh3.googleusercontent.c… 2025-03-12 2025-03-12
URL https://olsiop.shop/page?m=veri… 2025-03-12 2025-03-12
URL https://www.dropbox.com/referra… 2025-03-12 2025-03-12
URL https://RRGrg3yur78ewgewFf@acie… 2025-03-12 2025-03-12
DOMAIN weakandstrong.com 2025-03-12 2025-03-12
DOMAIN diagandcall.com 2025-03-12 2025-03-12
DOMAIN acieodls.shop 2025-03-12 2025-03-12
DOMAIN olsiop.shop 2025-03-12 2025-03-12
HASH aaecb10ca453bec3bb95bedac6d773a… 2024-10-08 2025-03-12
IPv4 159.100.13.216 2024-09-05 2025-03-12

Related Actors

Related Reports

« Back