북한 해킹 단체 Konni(코니)에서는 만든 업비트 사칭 악성코드-첨부1_성명_개인정보수집이용동의서.docx.lnk(2024.03.07)
2024-03-11 • Sakai • Upbit impersonation malware created by North Korean hacking group Konni - Attachment 1_Statement_Personal Information Collection and Use Agreement.docx.lnk (2024.03.07) •
A Korean write-up analyzes malware attributed by the author to the North Korean Konni group and disguised as an Upbit-related document package. The attack uses a ZIP archive containing a malicious LNK named like a personal-information consent DOCX file and a decoy mail-reference file; opening the LNK launches heavily obfuscated PowerShell. The script extracts embedded data from the shortcut, writes a DOCX and a CAB file under public locations, expands the archive, runs VBS and batch components, and proceeds with follow-on execution and cleanup. The evidence supports Konni-linked cryptocurrency-themed social engineering and a PowerShell/LNK delivery chain rather than a broader claim about confirmed theft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 27cd090cf83877750416d37dc6ddd8f… | 2024-03-11 | 2024-06-17 |
| URL | https://goosess.com/read/get.php | 2024-03-11 | 2024-06-17 |
| DOMAIN | stuckss.com | 2024-03-11 | 2024-06-17 |
| DOMAIN | goosess.com | 2024-03-11 | 2024-06-17 |
| HASH | 7a4a32b57bb087f3bfe0a640bd06810… | 2024-03-11 | 2024-03-26 |
| URL | http://stuckss.com/list.php | 2024-03-11 | 2024-03-26 |
| URL | http://stuckss.com/upload.php | 2024-03-11 | 2024-03-26 |
| HASH | deb57f8c9d1aaf45dba7f9eda16ccde… | 2024-03-11 | 2024-03-11 |