Konni APT exploits WinRAR vulnerability (CVE-2023-38831) targeting the cryptocurrency industry

2023-09-18 Knownsec

https://paper.seebug.org/3033/

Thumbnail for Konni APT exploits WinRAR vulnerability (CVE-2023-38831) targeting the cryptocurrency industry

Knownsec 404 reported Konni activity against the cryptocurrency industry using a WinRAR CVE-2023-38831 lure named around Qbao Network wallet screenshots. The crafted RAR caused WinRAR to execute an embedded file disguised as an HTML document when the victim opened the visible HTML lure. The payload contacted e9f0dkd.c1[.]biz, downloaded and unpacked batch and DLL components, then selected UAC bypass methods before running trap.bat and related payloads. The source frames the activity as notable because it shows a North Korean affiliated group other than Lazarus targeting cryptocurrency and exploiting the WinRAR vulnerability in an APT operation.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 1536e9bf086982c072c2cba7d42b0a62 2023-09-14 2023-09-18
DOMAIN ske9dhn.c1.biz 2023-09-14 2023-09-18
DOMAIN e9f0dkd.c1.biz 2023-09-14 2023-09-18

Related Actors

Related Reports

« Back