techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

4.8K
active users

#konni

1 post1 participant0 posts today
lazarusholic<p>"북한 해킹 단체 코니(Konni) 에서 만든 악성코드-가상자산 관련 외부평가위원 위촉 안내.hwp(2025.5.2)" published by Sakai. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://wezard4u.tistory.com/429498" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">wezard4u.tistory.com/429498</span><span class="invisible"></span></a></p>
lazarusholic<p>"북한 코니(Konni)KB국민은행 외국환거래 소명자료 제출서 위장한 악성코드-소명자료 제출 안내서(2025.5.13)" published by Sakai. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://wezard4u.tistory.com/429495" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">wezard4u.tistory.com/429495</span><span class="invisible"></span></a></p>
lazarusholic<p>"2025년 4월 APT 그룹 동향 보고서" published by Ahnlab. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/Lazarus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lazarus</span></a>, <a href="https://infosec.exchange/tags/SyncHole" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SyncHole</span></a>, <a href="https://infosec.exchange/tags/Trend" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trend</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://asec.ahnlab.com/ko/87992/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">asec.ahnlab.com/ko/87992/</span><span class="invisible"></span></a></p>
lazarusholic<p>"April 2025 APT Group Trends" published by Ahnlab. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/Lazarus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lazarus</span></a>, <a href="https://infosec.exchange/tags/Trend" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trend</span></a>, <a href="https://infosec.exchange/tags/SyncHole" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SyncHole</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://asec.ahnlab.com/en/88063/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">asec.ahnlab.com/en/88063/</span><span class="invisible"></span></a></p>
lazarusholic<p>"ESET APT Activity Report Q4 2024–Q1 2025" published by ESET. <a href="https://infosec.exchange/tags/Bybit" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Bybit</span></a>, <a href="https://infosec.exchange/tags/DeceptiveDevelopment" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DeceptiveDevelopment</span></a>, <a href="https://infosec.exchange/tags/Kimsuky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kimsuky</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/Trend" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trend</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2024-q1-2025/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">welivesecurity.com/en/eset-res</span><span class="invisible">earch/eset-apt-activity-report-q4-2024-q1-2025/</span></a></p>
Threat Insight<p>A new blog by Proofpoint reveals Feb 2025 activity by TA406 (<a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>), a North Korean-aligned advanced persistent threat.</p><p><a href="https://infosec.exchange/tags/TA406" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TA406</span></a> targeted government entities in Ukraine with phishing campaigns to deliver malware and harvest credentials.</p><p>Read the details: <a href="https://brnw.ch/21wSCmF" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">brnw.ch/21wSCmF</span><span class="invisible"></span></a>.</p><p>Highlights:</p><p>- The campaign goal is likely to collect intel on the trajectory of the Russian invasion</p><p>- The lure content is based heavily on recent events in Ukrainian politics</p><p>- Malware was delivered through emails via PowerShell infection chain and file hosting service MEGA</p><p>- TA406 also attempted to gather credentials by sending fake Microsoft security alert messages to Ukrainian government entities.</p><p>- Credential harvesting campaigns took place prior to the attempted HTML malware deployments and targeted some of the same users.</p><p>Why this matters: Proofpoint assesses TA406 is targeting Ukrainian government entities to better understand the appetite to continue fighting against the Russian invasion and assess the medium-term outlook of the conflict.</p>
lazarusholic<p>"북한 Konni(코니) 에서 만든 한국인터넷진흥원 사칭 악성코드-KISA 알림.pdf.lnk(2025.5.8)" published by Sakai. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="http://wezard4u.tistory.com/429485" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">http://</span><span class="">wezard4u.tistory.com/429485</span><span class="invisible"></span></a></p>
lazarusholic<p>"북한 해킹조직 코니(Konni) 위장문서 부가세납부서(국세징수법 시행규칙) 악용한 악성코드 유포(2025.4.28)" published by Sakai. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://wezard4u.tistory.com/429478" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">wezard4u.tistory.com/429478</span><span class="invisible"></span></a></p>
lazarusholic<p>"제안서로 위장을 하고 있는 북한 코니(Konni) 에서 만든 악성코드-제안서(2025.4.11)" published by Sakai. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://wezard4u.tistory.com/429464" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">wezard4u.tistory.com/429464</span><span class="invisible"></span></a></p>
lazarusholic<p>"A Deep Dive Into a Multi-Stage Malware Campaign Potentially Linked to DPRK’s Konni Group" published by navneet. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://muff-in.github.io/blog/Malware-Campaign-Potentially-Linked-to-DPRK-Konni-Group/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">muff-in.github.io/blog/Malware</span><span class="invisible">-Campaign-Potentially-Linked-to-DPRK-Konni-Group/</span></a></p>
lazarusholic<p>"한글 문서로 위장한 두 공격 그룹의 악성코드 비교" published by Logpresso. <a href="https://infosec.exchange/tags/APT37" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APT37</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/RokRAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RokRAT</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://logpresso.com/ko/blog/2025-04-17-cti-report-vol11" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">logpresso.com/ko/blog/2025-04-</span><span class="invisible">17-cti-report-vol11</span></a></p>
lazarusholic<p>"2025년 3월 APT 그룹 동향 보고서" published by Ahnlab. <a href="https://infosec.exchange/tags/Kimsuky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kimsuky</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/Lazarus" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Lazarus</span></a>, <a href="https://infosec.exchange/tags/Trend" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Trend</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://asec.ahnlab.com/ko/87480/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">asec.ahnlab.com/ko/87480/</span><span class="invisible"></span></a></p>
lazarusholic<p>"공격자간 협력 사례 공유" published by Plainbit. <a href="https://infosec.exchange/tags/Kimsuky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kimsuky</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/Slides" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Slides</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://www.dailysecu.com/form/html/k-cti/image/2025/down-11.pdf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">dailysecu.com/form/html/k-cti/</span><span class="invisible">image/2025/down-11.pdf</span></a></p>
lazarusholic<p>"주요 APT그룹 대상 최신 위협 인텔리전스 사례 분석" published by ENKI. <a href="https://infosec.exchange/tags/Kimsuky" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Kimsuky</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/Slides" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Slides</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://www.dailysecu.com/form/html/k-cti/image/2025/down-08.pdf" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">dailysecu.com/form/html/k-cti/</span><span class="invisible">image/2025/down-08.pdf</span></a></p>
lazarusholic<p>"북한 해킹 그룹 Konni(코니)에서 만든 악성코드-ECRM.M.hwp.lnk(&lt;-가칭,2025.3.24)" published by Sakai. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://wezard4u.tistory.com/429451" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">wezard4u.tistory.com/429451</span><span class="invisible"></span></a></p>
lazarusholic<p>"North Korea-Linked Konni APT Group – Active IOCs" published by Rewterz. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://rewterz.com/threat-advisory/north-korea-linked-konni-apt-group-active-iocs-14" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">rewterz.com/threat-advisory/no</span><span class="invisible">rth-korea-linked-konni-apt-group-active-iocs-14</span></a></p>
lazarusholic<p>"Analyzing spear-phishing campaign by Konni APT" published by PriyaPatel. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://prii308.github.io/Analyzing-spear-phishing-campaign-by-Konni-APT/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">prii308.github.io/Analyzing-sp</span><span class="invisible">ear-phishing-campaign-by-Konni-APT/</span></a></p>
lazarusholic<p>"경찰청과 국가인권위를 사칭한 Konni APT 캠페인 분석" published by Genians. <a href="https://infosec.exchange/tags/AutoIt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AutoIt</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://www.genians.co.kr/blog/threat_intelligence/konni_disguise" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">genians.co.kr/blog/threat_inte</span><span class="invisible">lligence/konni_disguise</span></a></p>
lazarusholic<p>"Analysis of Konni RAT: Stealth, Persistence, and Anti-Analysis Techniques" published by Cyfirma. <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://www.cyfirma.com/research/analysis-of-konni-rat-stealth-persistence-and-anti-analysis-techniques/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cyfirma.com/research/analysis-</span><span class="invisible">of-konni-rat-stealth-persistence-and-anti-analysis-techniques/</span></a></p>
lazarusholic<p>"Amenințări avansate: KONNI Campanie curentă de phishing" published by RODNSC. <a href="https://infosec.exchange/tags/AsyncRAT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AsyncRAT</span></a>, <a href="https://infosec.exchange/tags/Konni" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Konni</span></a>, <a href="https://infosec.exchange/tags/LNK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LNK</span></a>, <a href="https://infosec.exchange/tags/DPRK" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DPRK</span></a>, <a href="https://infosec.exchange/tags/CTI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CTI</span></a> <a href="https://dnsc.ro/citeste/amenintari-avansate-konni-campanie-curent-de-phishing" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">dnsc.ro/citeste/amenintari-ava</span><span class="invisible">nsate-konni-campanie-curent-de-phishing</span></a></p>