#StiffBizon

Incident/Operation

2022-07-20 • STIFF#BIZON Detection Using Securonix – New Attack Campaign Observed Possibly Linked to Konni/APT37 (North Korea)

STIFF#BIZON is a 2022 phishing campaign against high-value targets in the Czech Republic, Poland, and other countries. Its tradecraft and artifacts were assessed as possibly linked to Konni or APT37, but the attribution was not definitive. The campaign delivered a Konni-based remote-access trojan inside compressed email attachments, using a malicious Windows shortcut and a decoy document with a military theme; the malware supported persistence and privilege elevation on compromised hosts.

Tagged Reports

« Back