pu NK-003

2024-08-22 • S2WThreat Tracking: Analysis of puNK-003’s Lilith RA…

puNK-003 is a threat cluster tracked by S2W's TALON research team, designated in an August 2024 report on a malicious Windows shortcut (.lnk) file, disguised as tax-evasion supporting documents, that S2W hunted on VirusTotal in April 2024. When run, the shortcut, named CURKON by S2W, executes a hidden PowerShell command that drops a decoy document, copies curl.exe into a hidden folder, and downloads an AutoIt3 interpreter with an AutoIt-scripted reimplementation of the open-source Lilith RAT, which connects to a hardcoded command-and-control server to give attackers a reverse shell, persisting via scheduled tasks configured differently depending on whether Avast antivirus is detected, with command-and-control traffic proxied through compromised WordPress sites. S2W assessed puNK-003 as related to, yet distinct from, the Konni group, citing shared LNK-argument obfuscation, overlapping AutoIt-reimplementation code including an identical function shared with Konni's AutoIt-ported Amadey malware, and matching AutoIt3 executable versions, while noting CURKON functions only as a downloader, unlike Konni's dropper-style LINKON malware.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster