Konni 그룹의 스피어피싱·카카오톡 연계 위협 캠페인 분석
2026-03-15 • Genians • Analysis of Konni Group Spear-Phishing and KakaoTalk-Linked Threat Campaign •
https://www.genians.co.kr/blog/threat_intelligence/kakaotalk
Genians Security Center links the activity to the Konni APT group and describes a spear-phishing campaign that used a North Korean human-rights lecturer appointment lure to gain initial access. Victims were induced to run a malicious LNK file that launched 32-bit PowerShell, decrypted and opened a decoy PDF from inside the shortcut, downloaded AutoIt components from drfeysal[.]com, and created a scheduled task named APDNHFU for one-minute recurring execution. The follow-on APDNHFU.pdf payload was not a real PDF but an AutoIt container padded with dummy data and identified as EndRAT-like malware, using mutex Global\B073W15Z-D8QD-87B1-7465-CE77A8819E701 and custom socket C2 to 185.21.14[.]249 on port 80. The campaign also abused the victim's KakaoTalk PC session to send malicious files to selected contacts, turning trusted messenger relationships into a second-stage distribution channel. The combination of long-term endpoint persistence, document theft, messenger-session abuse, and account-based propagation makes the activity important for monitoring DPRK-themed social-engineering operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 7dc50e8af0070e544bff5299405cd3b9 | 2026-03-15 | 2026-03-15 |
| HASH | 461ade40b800ae80a40985594e1ac236 | 2026-03-15 | 2026-03-15 |
| HASH | 3288c284561055044c489567fd630ac2 | 2026-03-15 | 2026-03-15 |
| HASH | 2e1b0ac49313873a0e0b982c591a5264 | 2026-03-15 | 2026-03-15 |
| HASH | 148405ff05bf15a6a053e4e7c1795d40 | 2026-03-15 | 2026-03-15 |
| HASH | 01022facb38cf60b052e65a682f4a127 | 2026-03-15 | 2026-03-15 |
| DOMAIN | drfeysal.com | 2026-03-15 | 2026-03-15 |
| IPv4 | 96.62.214.5 | 2026-03-15 | 2026-03-15 |
| IPv4 | 157.180.88.26 | 2026-03-15 | 2026-03-15 |
| IPv4 | 185.21.14.249 | 2026-03-15 | 2026-03-15 |
| IPv4 | 178.16.54.208 | 2026-03-15 | 2026-03-15 |
| HASH | 61f65bd593ea0e52ac0dfdc6bc9cd73a | 2024-07-31 | 2026-03-15 |