STIFF#BIZON Detection Using Securonix – New Attack Campaign Observed Possibly Linked to Konni/APT37 (North Korea)

2022-07-20 Securonix

https://www.securonix.com/blog/stiffbizon-detection-new-attack-campaign-observed/

Thumbnail for STIFF#BIZON Detection Using Securonix – New Attack Campaign Observed Possibly Linked to Konni/APT37 (North Korea)

Securonix tracked STIFF#BIZON as an ongoing campaign against high-value targets including the Czech Republic and Poland, with some observed artifacts and tradecraft associated with Konni activity linked in the report to North Korea’s APT37. The intrusion began with phishing attachments containing a compressed archive with missile.docx and _weapons.doc.lnk; shortcut execution ran Base64 content appended to the document and launched a PowerShell stager. Follow-on stages downloaded weapons.doc and wp.vbs, created an "Office Update" scheduled task, established C2 communication, and loaded .NET modules for screenshots, Chromium state-key extraction, saved-login theft, and an interactive shell. The report also describes persistence through replacement of the Windows parental control service with malicious DLL and configuration files, making the activity relevant for defenders tracking Konni-style post-exploitation and credential theft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 185.176.43.106 2021-03-10 2024-11-08
HASH b6987a717741329d5b64f769c9d3f1f… 2022-07-20 2022-07-20
HASH 9f27430ed919e74c81b0487542fe29a… 2022-07-20 2022-07-20
HASH 5fce9f27326549cc6091ba1f806e7c1… 2022-07-20 2022-07-20
HASH 9c82477eac14abfb7f507806a941e4e… 2022-07-20 2022-07-20
HASH 35d38eed9168c16d2dd595fa9542a41… 2022-07-20 2022-07-20
HASH 07b10c5a772f6f3136eb58a7034bcb5… 2022-07-20 2022-07-20
HASH 6f325fb0a7de6f05490f1eb3c0e5826… 2022-07-20 2022-07-20
HASH 5d28072d76bd6af944fcec8045cbc24… 2022-07-20 2022-07-20
HASH b9727fb553894d857900c0a18f82723… 2022-07-20 2022-07-20
HASH 44566d506e0348c999a66ee5158b001… 2022-07-20 2022-07-20
HASH 31a9801e5e2e5fd7f66f23bc8456069… 2022-07-20 2022-07-20
HASH 5f3483823342318c4154bbef806cec2… 2022-07-20 2022-07-20
HASH dee7826f5b7f0cbc97a81de8f6844a0… 2022-07-20 2022-07-20
HASH 12df9753abd867118ce97e6570c2bde… 2022-07-20 2022-07-20
URL http://547857.c1.biz/dn.php?nam… 2022-07-20 2022-07-20
DOMAIN pull.net 2022-07-20 2022-07-20
DOMAIN chkey.net 2022-07-20 2022-07-20
DOMAIN 547857.c1.biz 2022-07-20 2022-07-20
DOMAIN 65487.c1.biz 2022-07-20 2022-07-20
DOMAIN capture.net 2022-07-20 2022-07-20
DOMAIN shell.net 2022-07-20 2022-07-20

Related Actors

Related Reports

2022-04-29 • 28% Match
#Trend #BlackBanshee #BlackAlicanto #T1082 #T1059.003 #T1090 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1112 #T1083 #T1204.001 #T1036 #T1027 #T1204.002 #T1071 #T1124 #T1204 #T1057 #T1059.005 #T1566.001 #T1547.001 #T1053.005 #T1132.001 #T1566 #T1059 #T1003 #T1105 #T1620 #T1486 #T1135 #T1078 #T1548 #T1190 #T1592 #T1049 #T1087 #T1589 #T1074.001 #T1591 #T1547 #T1068 #T1573 #T1095 #T1048 #T1608 #T1070 #T1056 #T1036.007 #T1614.001 #T1033 #T1110 #T1221 #T1132 #T1570 #T1021 #T1615 #T1482 #T1210 #T1069 #T1595 #T1039 #T1016.001
Shares tags: T1082, T1059.003, T1070.004
« Back