假面之下:Konni组织冒充政府软件安装包攻击剖析
2024-05-31 • Qihoo360 • Under the Mask: Analysis of Konni Group's Attack Impersonating a Government Software Installer •
Konni is a North Korea-linked threat actor that targeted government-related users with MSI installer packages masquerading as legitimate software, including a Russian foreign-ministry-style statistics application. The report explains that the installer drops decoy program components while malicious behavior runs silently in the background, supporting espionage against Russian, Korean, and neighboring government-sector targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 62b0e3ab7d2f1e15de5652ab6f3af50… | 2024-05-31 | 2024-09-05 |
| HASH | 33cc61eebe7c7c489fc978a20b4c8ad… | 2024-05-31 | 2024-09-05 |
| HASH | 58bcd90f6f04c005c892267a3dfe91d… | 2024-02-21 | 2024-09-05 |
| DOMAIN | victory-2024.mywebcommunity.org | 2024-02-21 | 2024-09-05 |
| HASH | 6810d356cf0d0c7fc4452caad4cbc864 | 2024-05-31 | 2024-05-31 |
| URL | http://victory-2024.mywebcommun… | 2024-05-31 | 2024-05-31 |
| HASH | 9339eaf1d77bb0324e393a08a6180fe… | 2024-02-21 | 2024-05-31 |
Related Actors
Related Reports
Shares tag: Konni • Shares 4 IOCs
2024-02-21 •
82% Match
To Russia With Love: Assessing a KONNI-Backdoored Suspected Russian Consular Software Installer
DCSO
Shares tag: Konni • Shares 3 IOCs
Shares tag: Konni • Published within a month
Shares tag: Konni • Published within a month
Shares tag: Konni • Published within a week
Shares tag: Konni • Published within a month