假面之下:Konni组织冒充政府软件安装包攻击剖析

2024-05-31 Qihoo360 Under the Mask: Analysis of Konni Group's Attack Impersonating a Government Software Installer

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247498655&idx=1&sn=ef69d0e4f5ab2f63049bafb485fdb395

Thumbnail for 假面之下:Konni组织冒充政府软件安装包攻击剖析

Konni is a North Korea-linked threat actor that targeted government-related users with MSI installer packages masquerading as legitimate software, including a Russian foreign-ministry-style statistics application. The report explains that the installer drops decoy program components while malicious behavior runs silently in the background, supporting espionage against Russian, Korean, and neighboring government-sector targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 62b0e3ab7d2f1e15de5652ab6f3af50… 2024-05-31 2024-09-05
HASH 33cc61eebe7c7c489fc978a20b4c8ad… 2024-05-31 2024-09-05
HASH 58bcd90f6f04c005c892267a3dfe91d… 2024-02-21 2024-09-05
DOMAIN victory-2024.mywebcommunity.org 2024-02-21 2024-09-05
HASH 6810d356cf0d0c7fc4452caad4cbc864 2024-05-31 2024-05-31
URL http://victory-2024.mywebcommun… 2024-05-31 2024-05-31
HASH 9339eaf1d77bb0324e393a08a6180fe… 2024-02-21 2024-05-31

Related Actors

Related Reports

« Back