New Konni Campaign Kicks Off The New Year By Targeting Russian Ministry Of Foreign Affairs
2022-01-05 • Lumen •
https://blog.lumen.com/new-konni-campaign-targeting-russian-ministry-of-foreign-affairs/
In October 2021, a presumed phishing campaign targeted the Russian Federation MID with links to a series of spoofed MID portals to harvest credentials from MID personnel. Based on the observed TTPs, including the use of a light-weight loader to retrieve a .cab file comprised of install.bat, the use of .dll to call an .ini file, the host-based commands and similar URL structures for the C2s, we observe strong correlation with the malware previously reported as Konni. After gaining access through stolen credentials, the actor was able to exploit trusted connections to distribute and load the malware, first by impersonating a government software program coinciding with new Covid mandates, and then through sending trojanized files from a compromised account. While this particular campaign was highly targeted, it is vital for defenders to understand the evolving capabilities of advanced actors to achieve infection of coveted targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | victory-2020.atwebpages.com | 2022-01-05 | 2024-09-05 |
| DOMAIN | h378576.atwebpages.com | 2022-01-05 | 2024-09-05 |
| [email protected] | 2022-01-05 | 2022-01-05 | |
| [email protected] | 2022-01-05 | 2022-01-05 | |
| [email protected] | 2022-01-05 | 2022-01-05 | |
| URL | http://h378576.atwebpages.com | 2022-01-05 | 2022-01-05 |
| URL | http://i758769.atwebpages.com | 2022-01-05 | 2022-01-05 |
| URL | http://i758769.atwebpages.com/i… | 2022-01-05 | 2022-01-05 |
| URL | http://h378576.atwebpages.com/u… | 2022-01-05 | 2022-01-05 |
| DOMAIN | portal.newint-mid.ru.carnegiein… | 2022-01-05 | 2022-01-05 |
| DOMAIN | pronto-login.com | 2022-01-05 | 2022-01-05 |
| DOMAIN | passport.yandex.ru-settings.pro… | 2022-01-05 | 2022-01-05 |
| DOMAIN | e.mail.ru.settings.pronto-login… | 2022-01-05 | 2022-01-05 |
| DOMAIN | i758769.atwebpages.com | 2022-01-05 | 2022-01-05 |
| DOMAIN | carnegieinsider.com | 2022-01-05 | 2022-01-05 |
| IPv4 | 152.89.247.26 | 2022-01-05 | 2022-01-05 |
| DOMAIN | mid.ru | 2020-03-02 | 2022-01-05 |