#CoinPlan

Incident/Operation

2019-10-01 • 코니(Konni) APT 조직, HWP 취약점을 이용한 'Coin Plan' 작전 감행

CoinPlan was an October 2019 Konni campaign that used a Korean-language HWP document themed as a cryptocurrency-mining marketing plan. The malicious document embedded encoded PostScript and shellcode that exploited the document-processing environment, contacted attacker-controlled infrastructure, downloaded scripted stages, unpacked a cabinet archive, and collected system information for exfiltration. The activity was assessed as likely state-sponsored and closely related to Kimsuky, but the attribution was expressed as a strong linkage rather than a definitive organizational identity.

Tagged Reports

« Back