Russian Ministry Software Backdoored with North Korean KONNI Malware
ID: 8c2c65aa-d110-5ad1-a401-42c8c9dffcb5
STIX ID: report--8c2c65aa-d110-5ad1-a401-42c8c9dffcb5
Feed Name: HackRead
German firm DCSO identified a KONNI malware sample (uploaded to VirusTotal in Jan 2024) linked to DPRK-associated actors and targeting the Russian Ministry of Foreign Affairs by backdooring a Russian consular software installer (Statistika KZU). The report details KONNI's capabilities (MSI-based deployment, AES-CTR encrypted C2, HTTP comms, file upload/download, CAB compression), delivery via a compromised installer containing user manuals, and contextualizes the finding with previous KONNI campaigns and geopolitical ramifications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
