KONNI: A Malware Under The Radar For Years

2017-05-03 Cisco Talos

https://blog.talosintelligence.com/2017/05/konni-malware-under-radar-for-years.html

Thumbnail for KONNI: A Malware Under The Radar For Years

KONNI campaigns observed from 2014 to 2017 used spear-phishing attachments and social engineering to make victims open .scr droppers that displayed decoy documents before executing malware. The malware evolved from a one-time information stealer into a multi-component RAT with keylogging, clipboard theft, file upload and download, command execution, screenshot capture, and improved instruction handling. Several campaigns used decoys tied to North Korea themes or public organizations linked to North Korea, including UN, UNICEF, embassy, and agency contact lists. Infrastructure was hosted on free web-hosting domains such as 000webhost, with C2 paths including login.php, upload.php, download.php, and uploadtm.php. The reuse of files, code, and checks for artifacts from earlier versions suggests repeat targeting and a long-running, technically improving operation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3de491de3f39c599954bdbf08bba3ba… 2017-05-03 2017-05-03
HASH 94113c9968db13e3412c1b9c1c88259… 2017-05-03 2017-05-03
HASH 44150350727e2a42f66d50015e98de4… 2017-05-03 2017-05-03
HASH 553a475f72819b295927e469c7bf9ae… 2017-05-03 2017-05-03
HASH dd730cc8fcbb979eb366915397b8535… 2017-05-03 2017-05-03
HASH 640477943ad77fb2a74752f4650707e… 2017-05-03 2017-05-03
HASH 413772d81e4532fec5119e9dce5e2bf… 2017-05-03 2017-05-03
HASH 92600679bb183c1897e7e1e64460821… 2017-05-03 2017-05-03
HASH 39bc918f0080603ac80fe1ec2edfd30… 2017-05-03 2017-05-03
HASH 56f159cde3a55ae6e9270d95791ef2f… 2017-05-03 2017-05-03
HASH 4585584fe7e14838858b24c18a792b1… 2017-05-03 2017-05-03
HASH 69a9d7aa0cb964c091ca128735b6e60… 2017-05-03 2017-05-03
HASH eb90e40fc4d91dec68e8509056c52e9… 2017-05-03 2017-05-03
DOMAIN dowhelsitjs.netau.net 2017-05-03 2017-05-03
DOMAIN phpschboy.prohosts.org 2017-05-03 2017-05-03
DOMAIN pactchfilepacks.net23.net 2017-05-03 2017-05-03

Related Actors

Related Reports

« Back