Konni APT exploits WinRAR vulnerability (CVE-2023-38831) targeting the cryptocurrency industry

2023-09-18 • Knownsec •

https://paper.seebug.org/3033/

Thumbnail for Konni APT exploits WinRAR vulnerability (CVE-2023-38831) targeting the cryptocurrency industry

Knownsec 404 reported Konni activity against the cryptocurrency industry using a WinRAR CVE-2023-38831 lure named around Qbao Network wallet screenshots. The crafted RAR caused WinRAR to execute an embedded file disguised as an HTML document when the victim opened the visible HTML lure. The payload contacted e9f0dkd.c1[.]biz, downloaded and unpacked batch and DLL components, then selected UAC bypass methods before running trap.bat and related payloads. The source frames the activity as notable because it shows a North Korean affiliated group other than Lazarus targeting cryptocurrency and exploiting the WinRAR vulnerability in an APT operation.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ske9dhn.c1.biz 2023-09-14 2023-09-18
DOMAIN e9f0dkd.c1.biz 2023-09-14 2023-09-18
HASH d0068a7c62bafd0078829a0597fa5cc… 2023-01-30 2023-09-18

Related Actors

Related Reports

« Back