New Konni Campaign Kicks Off The New Year By Targeting Russian Ministry Of Foreign Affairs

2022-01-05 Lumen

https://blog.lumen.com/new-konni-campaign-targeting-russian-ministry-of-foreign-affairs/

Thumbnail for New Konni Campaign Kicks Off The New Year By Targeting Russian Ministry Of Foreign Affairs

In October 2021, a presumed phishing campaign targeted the Russian Federation MID with links to a series of spoofed MID portals to harvest credentials from MID personnel. Based on the observed TTPs, including the use of a light-weight loader to retrieve a .cab file comprised of install.bat, the use of .dll to call an .ini file, the host-based commands and similar URL structures for the C2s, we observe strong correlation with the malware previously reported as Konni. After gaining access through stolen credentials, the actor was able to exploit trusted connections to distribute and load the malware, first by impersonating a government software program coinciding with new Covid mandates, and then through sending trojanized files from a compromised account. While this particular campaign was highly targeted, it is vital for defenders to understand the evolving capabilities of advanced actors to achieve infection of coveted targets.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN victory-2020.atwebpages.com 2022-01-05 2024-09-05
DOMAIN h378576.atwebpages.com 2022-01-05 2024-09-05
EMAIL [email protected] 2022-01-05 2022-01-05
EMAIL [email protected] 2022-01-05 2022-01-05
EMAIL [email protected] 2022-01-05 2022-01-05
URL http://h378576.atwebpages.com 2022-01-05 2022-01-05
URL http://i758769.atwebpages.com 2022-01-05 2022-01-05
URL http://i758769.atwebpages.com/i… 2022-01-05 2022-01-05
URL http://h378576.atwebpages.com/u… 2022-01-05 2022-01-05
DOMAIN portal.newint-mid.ru.carnegiein… 2022-01-05 2022-01-05
DOMAIN pronto-login.com 2022-01-05 2022-01-05
DOMAIN passport.yandex.ru-settings.pro… 2022-01-05 2022-01-05
DOMAIN e.mail.ru.settings.pronto-login… 2022-01-05 2022-01-05
DOMAIN i758769.atwebpages.com 2022-01-05 2022-01-05
DOMAIN carnegieinsider.com 2022-01-05 2022-01-05
IPv4 152.89.247.26 2022-01-05 2022-01-05
DOMAIN mid.ru 2020-03-02 2022-01-05

Related Actors

Related Reports

« Back