PULSE NAME
Analysis of Konni Group's spearphishing-Chaotalk tied threat campaign
WHITE Konni PetrP.73 2026-03-18 Modified: 2026-04-17
14
IOCs
MEDIUM VOLUME
The Konni Group, attributed to a North Korean advanced persistent threat (APT), has been involved in a sophisticated spearphishing campaign that exploits social engineering tactics to compromise targeted individuals. Initial access is achieved through emails masquerading as invitations for facilitating North Korean human rights sessions, leading to the execution of malicious LNK files. These files serve as droppers that download and install remote-controlled malware, allowing the attackers prolonged access for unauthorized information gathering, specifically internal documents.
Indicators of Compromise (14)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 01022facb38cf60b052e65a682f4a127 2026-03-18
FileHash-MD5 148405ff05bf15a6a053e4e7c1795d40 2026-03-18
FileHash-MD5 2e1b0ac49313873a0e0b982c591a5264 2026-03-18
FileHash-MD5 3288c284561055044c489567fd630ac2 2026-03-18
FileHash-MD5 461ade40b800ae80a40985594e1ac236 2026-03-18
FileHash-MD5 61f65bd593ea0e52ac0dfdc6bc9cd73a 2026-03-18
FileHash-MD5 7dc50e8af0070e544bff5299405cd3b9 2026-03-18
FileHash-SHA1 11ffeabbe42159e1365aa82463d8690c845ce7b7 SHA1 of 3288c284561055044c489567fd630ac2 2026-03-18
FileHash-SHA1 b3892eef846c044a2b0785d54a432b3e93a968c8 SHA1 of 461ade40b800ae80a40985594e1ac236 2026-03-18
FileHash-SHA1 e5adeecfb03cc7d26de2f11746d3aef6b1fd4830 SHA1 of 61f65bd593ea0e52ac0dfdc6bc9cd73a 2026-03-18
FileHash-SHA256 798af20db39280f90a1d35f2ac2c1d62124d1f5218a2a0fa29d87a13340bd3e4 SHA256 of 461ade40b800ae80a40985594e1ac236 2026-03-18
FileHash-SHA256 aa51573f9abcd4a1ec4a61ee7e5811c0279e015ea22bdb787780d67ce7153a57 SHA256 of 61f65bd593ea0e52ac0dfdc6bc9cd73a 2026-03-18
FileHash-SHA256 ac92d4c6397eb4451095949ac485ef4ec38501d7bb6f475419529ae67e297753 SHA256 of 3288c284561055044c489567fd630ac2 2026-03-18
domain drfeysal.com 2026-03-18