Konni의 최신 AsyncRAT 공격: LNK 파일을 활용한 감염 기법
2025-03-12 • ENKI • Konni's Latest AsyncRAT Attack: Infection Technique Using LNK Files •
https://www.enki.co.kr/media-center/blog/konni-s-asyncrat-attack-lnk-based-infection
ENKI links a set of VirusTotal-hunted LNK samples to Konni activity associated with North Korean operations and describes a multi-stage infection chain ending in an AsyncRAT variant. The LNK files extract and execute obfuscated PowerShell from embedded data, then retrieve additional JavaScript and PowerShell payloads through Dropbox, C2 servers, and Google Drive. The chain establishes persistence through scheduled tasks and HKCU Run keys, creates infection logs in an attacker-controlled Google Drive, and appears to use file polling or manual staging to deliver follow-on payloads. The final AsyncRAT resembles previously reported Konni-linked AsyncRAT code but receives its C2 IP and port as runtime arguments rather than relying only on hardcoded configuration, with 206.206.127[.]152 observed in the analyzed activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | 71532697854-ef1nlsl4cjn4scm57ds… | 2025-03-12 | 2025-05-19 |
| DOMAIN | 159263970130-1gil63rpicrhtbo4he… | 2025-03-12 | 2025-05-19 |
| IPv4 | 74.50.94.175 | 2025-03-12 | 2025-05-19 |
| HASH | 694af547d321771e69c48cf3c04411f… | 2025-03-12 | 2025-03-19 |
| HASH | 9af27198deefa87bb1d3868abb295f0… | 2025-03-12 | 2025-03-19 |
| HASH | 47abd1682a88f7aadd3fe57583a7edb… | 2025-03-12 | 2025-03-19 |
| HASH | 7a21d0e9793a4f115d395c6e99927d5… | 2025-03-12 | 2025-03-19 |
| HASH | 5967513540ad610ddbbc124f2437cf5… | 2025-03-12 | 2025-03-19 |
| HASH | 68621690299e676b7562aca350a4ab8… | 2025-03-12 | 2025-03-19 |
| HASH | 811d221a1340e64aa1736d9d4e8f808… | 2025-03-12 | 2025-03-19 |
| URL | https://lh3.googleusercontent.c… | 2025-03-12 | 2025-03-19 |
| IPv4 | 74.50.94.47 | 2025-03-12 | 2025-03-19 |
| HASH | 268640934dd1f0cfe3a365322185885… | 2025-02-21 | 2025-03-19 |
| IPv4 | 206.206.127.152 | 2024-10-08 | 2025-03-19 |
| HASH | 2ad3120e1b03317d8d588d0cc097cc4… | 2025-03-12 | 2025-03-12 |
| HASH | 52b8e4da732d06000e29d7609668021… | 2025-03-12 | 2025-03-12 |
| HASH | e6e3a8fb352641bb5b6f6db1479490d… | 2025-03-12 | 2025-03-12 |
| HASH | 11afe5cc28666c39d3dc3e9d51f780e… | 2025-03-12 | 2025-03-12 |
| HASH | f4c4f68f8b27279b00b718b02392d5d… | 2025-03-12 | 2025-03-12 |
| HASH | dfeec1052063d6dc69cc6d23ca0cd26… | 2025-03-12 | 2025-03-12 |
| HASH | 9c9df2d90602c915005811aabf44465… | 2025-03-12 | 2025-03-12 |
| HASH | 11ac6151182db3b41f9022b4e4b8a38… | 2025-03-12 | 2025-03-12 |
| HASH | f3aee5924279dd1883efbb04c891663… | 2025-03-12 | 2025-03-12 |
| HASH | aacb5aca178f6444a82bca1febb282a… | 2025-03-12 | 2025-03-12 |
| HASH | ba52ab256079f80fdf9c47bf5fc215f… | 2025-03-12 | 2025-03-12 |
| [email protected] | 2025-03-12 | 2025-03-12 | |
| [email protected] | 2025-03-12 | 2025-03-12 | |
| [email protected] | 2025-03-12 | 2025-03-12 | |
| URL | https://lh3.googleusercontent.c… | 2025-03-12 | 2025-03-12 |
| URL | https://olsiop.shop/page?m=veri… | 2025-03-12 | 2025-03-12 |
| URL | https://www.dropbox.com/referra… | 2025-03-12 | 2025-03-12 |
| URL | https://RRGrg3yur78ewgewFf@acie… | 2025-03-12 | 2025-03-12 |
| DOMAIN | weakandstrong.com | 2025-03-12 | 2025-03-12 |
| DOMAIN | diagandcall.com | 2025-03-12 | 2025-03-12 |
| DOMAIN | acieodls.shop | 2025-03-12 | 2025-03-12 |
| DOMAIN | olsiop.shop | 2025-03-12 | 2025-03-12 |
| HASH | aaecb10ca453bec3bb95bedac6d773a… | 2024-10-08 | 2025-03-12 |
| IPv4 | 159.100.13.216 | 2024-09-05 | 2025-03-12 |