Konni 그룹의 스피어피싱·카카오톡 연계 위협 캠페인 분석

2026-03-15 Genians Analysis of Konni Group Spear-Phishing and KakaoTalk-Linked Threat Campaign

https://www.genians.co.kr/blog/threat_intelligence/kakaotalk

Thumbnail for Konni 그룹의 스피어피싱·카카오톡 연계 위협 캠페인 분석

Genians Security Center links the activity to the Konni APT group and describes a spear-phishing campaign that used a North Korean human-rights lecturer appointment lure to gain initial access. Victims were induced to run a malicious LNK file that launched 32-bit PowerShell, decrypted and opened a decoy PDF from inside the shortcut, downloaded AutoIt components from drfeysal[.]com, and created a scheduled task named APDNHFU for one-minute recurring execution. The follow-on APDNHFU.pdf payload was not a real PDF but an AutoIt container padded with dummy data and identified as EndRAT-like malware, using mutex Global\B073W15Z-D8QD-87B1-7465-CE77A8819E701 and custom socket C2 to 185.21.14[.]249 on port 80. The campaign also abused the victim's KakaoTalk PC session to send malicious files to selected contacts, turning trusted messenger relationships into a second-stage distribution channel. The combination of long-term endpoint persistence, document theft, messenger-session abuse, and account-based propagation makes the activity important for monitoring DPRK-themed social-engineering operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7dc50e8af0070e544bff5299405cd3b9 2026-03-15 2026-03-15
HASH 461ade40b800ae80a40985594e1ac236 2026-03-15 2026-03-15
HASH 3288c284561055044c489567fd630ac2 2026-03-15 2026-03-15
HASH 2e1b0ac49313873a0e0b982c591a5264 2026-03-15 2026-03-15
HASH 148405ff05bf15a6a053e4e7c1795d40 2026-03-15 2026-03-15
HASH 01022facb38cf60b052e65a682f4a127 2026-03-15 2026-03-15
DOMAIN drfeysal.com 2026-03-15 2026-03-15
IPv4 96.62.214.5 2026-03-15 2026-03-15
IPv4 157.180.88.26 2026-03-15 2026-03-15
IPv4 185.21.14.249 2026-03-15 2026-03-15
IPv4 178.16.54.208 2026-03-15 2026-03-15
HASH 61f65bd593ea0e52ac0dfdc6bc9cd73a 2024-07-31 2026-03-15

Related Actors

Related Reports

« Back