Konni APT 组织以朝鲜疫情物资话题为诱饵的攻击活动分析
2021-02-01 • Anquanke • Analysis of attack activities organized by Konni APT using the topic of North Korean epidemic supplies as bait •
ThreatBook analyzed a Konni APT campaign using a North Korea COVID-19 supplies article as a lure document, consistent with the group’s long-running spear-phishing against South Korea and regional targets. The malicious Word document hid its text until macros were enabled, then downloaded a loader from a compromised site and executed it from the Templates directory. The loader decrypted and injected an Amadey-family backdoor, established persistence under C:\ProgramData\a7963\TlWorker.exe, collected host and security-product information, and beaconed by HTTP POST to 186.122.150[.]107/cc/index.php for follow-on module delivery. The report also describes infrastructure and tradecraft overlaps with Kimsuky, including related C2 registration details and macro-based delivery patterns, while treating the relationship as a hypothesis requiring continued tracking.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | rabadaun.com | 2021-02-01 | 2021-02-02 |
| HASH | d1baefd0bdc7f3b0369c5b7126c3b98… | 2021-02-01 | 2021-02-02 |
| HASH | efc139dc0e280a374065dc59c55a45b… | 2021-02-01 | 2021-02-02 |
| DOMAIN | fd-com.fr | 2021-02-01 | 2021-02-02 |
| IPv4 | 108.62.118.185 | 2021-02-01 | 2021-02-02 |
| IPv4 | 186.122.150.107 | 2021-02-01 | 2021-02-02 |
| HASH | 57b59b770f313b0a09b651bfba0c95c… | 2021-02-01 | 2021-02-01 |
| HASH | 9891b3d68ffbdb4a4bd0e7e49ba7b1e… | 2021-02-01 | 2021-02-01 |
| HASH | 1e14de870b1c4b09cbf81206562a254… | 2021-02-01 | 2021-02-01 |
| HASH | f108a4d064dd05c0a097f517ec738b1a | 2021-02-01 | 2021-02-01 |
| HASH | 9aab5a536b95963c4e3c990ab40bdeb… | 2021-02-01 | 2021-02-01 |
| HASH | f160c057fded2c01bfdb65bb7aa9dfcc | 2021-02-01 | 2021-02-01 |
| HASH | 544aaf0804060598138f2db809c31bb… | 2021-02-01 | 2021-02-01 |
| HASH | 5bd48c2f61541124920d71e674ce3fd… | 2021-02-01 | 2021-02-01 |
| HASH | f197a7be7fdb286bc9673a57b54994c… | 2021-02-01 | 2021-02-01 |
| [email protected] | 2021-02-01 | 2021-02-01 | |
| [email protected] | 2021-02-01 | 2021-02-01 | |
| [email protected] | 2021-02-01 | 2021-02-01 | |
| [email protected] | 2021-02-01 | 2021-02-01 | |
| URL | http://fd-com.fr/wp-content/the… | 2021-02-01 | 2021-02-01 |
| URL | http://documentserver.site/dark… | 2021-02-01 | 2021-02-01 |
| URL | http://securelevel.site/pppp/in… | 2021-02-01 | 2021-02-01 |
| URL | http://documentserver.site/dark… | 2021-02-01 | 2021-02-01 |
| URL | https://rabadaun.com/wordpress/… | 2021-02-01 | 2021-02-01 |
| DOMAIN | s.threatbook.cn | 2021-02-01 | 2021-02-01 |
| DOMAIN | documentserver.site | 2021-02-01 | 2021-02-01 |
| DOMAIN | securelevel.site | 2021-02-01 | 2021-02-01 |