Phishing Emails Used to Deploy KONNI Malware

2020-08-14 USCISA

https://us-cert.cisa.gov/ncas/alerts/aa20-227a

Thumbnail for Phishing Emails Used to Deploy KONNI Malware

CISA observed phishing emails carrying Microsoft Word documents with malicious VBA macros that deploy KONNI, a RAT capable of file theft, keylogging, screenshots, and arbitrary code execution. The macro tries to trick users into enabling content by changing text color, checks whether Windows is 32-bit or 64-bit, and builds command-line activity to download additional files. The infection chain uses CertUtil to retrieve and decode base64 content, silently copies and renames certutil.exe in a temporary directory, writes a decoded batch file, deletes the intermediate text file, and executes the batch script. Documented KONNI behavior includes system and user discovery, HTTP C2, FTP exfiltration, file deletion, PowerShell use, browser credential theft, registry and shortcut persistence, COM hijacking, UAC bypass, clipboard theft, and screenshot capture. CISA also provides Snort detections for KONNI traffic patterns such as /weget/ PHP paths and suspicious HTTP headers.

Related Actors

Related Reports

2020-08-26 • 50% Match
#BeagleBoyz #FASTCash2 #T1082 #T1119 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1020 #T1560 #T1115 #T1083 #T1036 #T1027 #T1071 #T1548.003 #T1204 #T1057 #T1059.005 #T1518.001 #T1566.001 #T1547.001 #T1059.001 #T1053 #T1132.001 #T1102 #T1059 #T1199 #T1105 #T1219 #T1055 #T1553.002 #T1552.004 #T1562.001 #T1486 #T1129 #T1489 #T1078 #T1133 #T1053.003 #T1190 #T1203 #T1189 #T1049 #T1098 #T1087 #T1016 #T1070.006 #T1021.001 #T1574.001 #T1217 #T1106 #T1573 #T1095 #T1056 #T1010 #T1021.002 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1110 #T1561.002 #T1202 #T1070.003 #T1565.001 #T1021 #T1505.003 #T1027.005 #T1056.004 #T1218.001 #T1562.003 #T1014 #T1053.004 #T1101 #T1565.002 #T1565.003 #T1562.006
Shares tags: T1082, T1140, T1070.004 • Same author: USCISA • Published within a month
« Back