KONNI: A Malware Under The Radar For Years
2017-05-03 • Cisco Talos •
https://blog.talosintelligence.com/2017/05/konni-malware-under-radar-for-years.html
KONNI campaigns observed from 2014 to 2017 used spear-phishing attachments and social engineering to make victims open .scr droppers that displayed decoy documents before executing malware. The malware evolved from a one-time information stealer into a multi-component RAT with keylogging, clipboard theft, file upload and download, command execution, screenshot capture, and improved instruction handling. Several campaigns used decoys tied to North Korea themes or public organizations linked to North Korea, including UN, UNICEF, embassy, and agency contact lists. Infrastructure was hosted on free web-hosting domains such as 000webhost, with C2 paths including login.php, upload.php, download.php, and uploadtm.php. The reuse of files, code, and checks for artifacts from earlier versions suggests repeat targeting and a long-running, technically improving operation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 3de491de3f39c599954bdbf08bba3ba… | 2017-05-03 | 2017-05-03 |
| HASH | 94113c9968db13e3412c1b9c1c88259… | 2017-05-03 | 2017-05-03 |
| HASH | 44150350727e2a42f66d50015e98de4… | 2017-05-03 | 2017-05-03 |
| HASH | 553a475f72819b295927e469c7bf9ae… | 2017-05-03 | 2017-05-03 |
| HASH | dd730cc8fcbb979eb366915397b8535… | 2017-05-03 | 2017-05-03 |
| HASH | 640477943ad77fb2a74752f4650707e… | 2017-05-03 | 2017-05-03 |
| HASH | 413772d81e4532fec5119e9dce5e2bf… | 2017-05-03 | 2017-05-03 |
| HASH | 92600679bb183c1897e7e1e64460821… | 2017-05-03 | 2017-05-03 |
| HASH | 39bc918f0080603ac80fe1ec2edfd30… | 2017-05-03 | 2017-05-03 |
| HASH | 56f159cde3a55ae6e9270d95791ef2f… | 2017-05-03 | 2017-05-03 |
| HASH | 4585584fe7e14838858b24c18a792b1… | 2017-05-03 | 2017-05-03 |
| HASH | 69a9d7aa0cb964c091ca128735b6e60… | 2017-05-03 | 2017-05-03 |
| HASH | eb90e40fc4d91dec68e8509056c52e9… | 2017-05-03 | 2017-05-03 |
| DOMAIN | dowhelsitjs.netau.net | 2017-05-03 | 2017-05-03 |
| DOMAIN | phpschboy.prohosts.org | 2017-05-03 | 2017-05-03 |
| DOMAIN | pactchfilepacks.net23.net | 2017-05-03 | 2017-05-03 |