STIFF#BIZON Detection Using Securonix – New Attack Campaign Observed Possibly Linked to Konni/APT37 (North Korea)
2022-07-20 • Securonix •
https://www.securonix.com/blog/stiffbizon-detection-new-attack-campaign-observed/
Securonix tracked STIFF#BIZON as an ongoing campaign against high-value targets including the Czech Republic and Poland, with some observed artifacts and tradecraft associated with Konni activity linked in the report to North Korea’s APT37. The intrusion began with phishing attachments containing a compressed archive with missile.docx and _weapons.doc.lnk; shortcut execution ran Base64 content appended to the document and launched a PowerShell stager. Follow-on stages downloaded weapons.doc and wp.vbs, created an "Office Update" scheduled task, established C2 communication, and loaded .NET modules for screenshots, Chromium state-key extraction, saved-login theft, and an interactive shell. The report also describes persistence through replacement of the Windows parental control service with malicious DLL and configuration files, making the activity relevant for defenders tracking Konni-style post-exploitation and credential theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 185.176.43.106 | 2021-03-10 | 2024-11-08 |
| HASH | b6987a717741329d5b64f769c9d3f1f… | 2022-07-20 | 2022-07-20 |
| HASH | 9f27430ed919e74c81b0487542fe29a… | 2022-07-20 | 2022-07-20 |
| HASH | 5fce9f27326549cc6091ba1f806e7c1… | 2022-07-20 | 2022-07-20 |
| HASH | 9c82477eac14abfb7f507806a941e4e… | 2022-07-20 | 2022-07-20 |
| HASH | 35d38eed9168c16d2dd595fa9542a41… | 2022-07-20 | 2022-07-20 |
| HASH | 07b10c5a772f6f3136eb58a7034bcb5… | 2022-07-20 | 2022-07-20 |
| HASH | 6f325fb0a7de6f05490f1eb3c0e5826… | 2022-07-20 | 2022-07-20 |
| HASH | 5d28072d76bd6af944fcec8045cbc24… | 2022-07-20 | 2022-07-20 |
| HASH | b9727fb553894d857900c0a18f82723… | 2022-07-20 | 2022-07-20 |
| HASH | 44566d506e0348c999a66ee5158b001… | 2022-07-20 | 2022-07-20 |
| HASH | 31a9801e5e2e5fd7f66f23bc8456069… | 2022-07-20 | 2022-07-20 |
| HASH | 5f3483823342318c4154bbef806cec2… | 2022-07-20 | 2022-07-20 |
| HASH | dee7826f5b7f0cbc97a81de8f6844a0… | 2022-07-20 | 2022-07-20 |
| HASH | 12df9753abd867118ce97e6570c2bde… | 2022-07-20 | 2022-07-20 |
| URL | http://547857.c1.biz/dn.php?nam… | 2022-07-20 | 2022-07-20 |
| DOMAIN | pull.net | 2022-07-20 | 2022-07-20 |
| DOMAIN | chkey.net | 2022-07-20 | 2022-07-20 |
| DOMAIN | 547857.c1.biz | 2022-07-20 | 2022-07-20 |
| DOMAIN | 65487.c1.biz | 2022-07-20 | 2022-07-20 |
| DOMAIN | capture.net | 2022-07-20 | 2022-07-20 |
| DOMAIN | shell.net | 2022-07-20 | 2022-07-20 |