Konni APT 组织以朝鲜疫情物资话题为诱饵的攻击活动分析

2021-02-01 Anquanke Analysis of attack activities organized by Konni APT using the topic of North Korean epidemic supplies as bait

https://www.anquanke.com/post/id/230116

Thumbnail for Konni APT 组织以朝鲜疫情物资话题为诱饵的攻击活动分析

ThreatBook analyzed a Konni APT campaign using a North Korea COVID-19 supplies article as a lure document, consistent with the group’s long-running spear-phishing against South Korea and regional targets. The malicious Word document hid its text until macros were enabled, then downloaded a loader from a compromised site and executed it from the Templates directory. The loader decrypted and injected an Amadey-family backdoor, established persistence under C:\ProgramData\a7963\TlWorker.exe, collected host and security-product information, and beaconed by HTTP POST to 186.122.150[.]107/cc/index.php for follow-on module delivery. The report also describes infrastructure and tradecraft overlaps with Kimsuky, including related C2 registration details and macro-based delivery patterns, while treating the relationship as a hypothesis requiring continued tracking.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN rabadaun.com 2021-02-01 2021-02-02
HASH d1baefd0bdc7f3b0369c5b7126c3b98… 2021-02-01 2021-02-02
HASH efc139dc0e280a374065dc59c55a45b… 2021-02-01 2021-02-02
DOMAIN fd-com.fr 2021-02-01 2021-02-02
IPv4 108.62.118.185 2021-02-01 2021-02-02
IPv4 186.122.150.107 2021-02-01 2021-02-02
HASH 57b59b770f313b0a09b651bfba0c95c… 2021-02-01 2021-02-01
HASH 9891b3d68ffbdb4a4bd0e7e49ba7b1e… 2021-02-01 2021-02-01
HASH 1e14de870b1c4b09cbf81206562a254… 2021-02-01 2021-02-01
HASH f108a4d064dd05c0a097f517ec738b1a 2021-02-01 2021-02-01
HASH 9aab5a536b95963c4e3c990ab40bdeb… 2021-02-01 2021-02-01
HASH f160c057fded2c01bfdb65bb7aa9dfcc 2021-02-01 2021-02-01
HASH 544aaf0804060598138f2db809c31bb… 2021-02-01 2021-02-01
HASH 5bd48c2f61541124920d71e674ce3fd… 2021-02-01 2021-02-01
HASH f197a7be7fdb286bc9673a57b54994c… 2021-02-01 2021-02-01
EMAIL [email protected] 2021-02-01 2021-02-01
EMAIL [email protected] 2021-02-01 2021-02-01
EMAIL [email protected] 2021-02-01 2021-02-01
EMAIL [email protected] 2021-02-01 2021-02-01
URL http://fd-com.fr/wp-content/the… 2021-02-01 2021-02-01
URL http://documentserver.site/dark… 2021-02-01 2021-02-01
URL http://securelevel.site/pppp/in… 2021-02-01 2021-02-01
URL http://documentserver.site/dark… 2021-02-01 2021-02-01
URL https://rabadaun.com/wordpress/… 2021-02-01 2021-02-01
DOMAIN s.threatbook.cn 2021-02-01 2021-02-01
DOMAIN documentserver.site 2021-02-01 2021-02-01
DOMAIN securelevel.site 2021-02-01 2021-02-01

Related Actors

Related Reports

« Back