← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Analysis of Konni Group's spearphishing-Chaotalk tied threat campaign
The Konni Group, attributed to a North Korean advanced persistent threat (APT), has been involved in a sophisticated spearphishing campaign that exploits social engineering tactics to compromise targeted individuals. Initial access is achieved through emails masquerading as invitations for facilitating North Korean human rights sessions, leading to the execution of malicious LNK files. These files serve as droppers that download and install remote-controlled malware, allowing the attackers prolonged access for unauthorized information gathering, specifically internal documents.
MITRE ATT&CK & Malware Families
Indicators of Compromise (14)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 01022facb38cf60b052e65a682f4a127 | — | 2026-03-18 | |
| FileHash-MD5 | 148405ff05bf15a6a053e4e7c1795d40 | — | 2026-03-18 | |
| FileHash-MD5 | 2e1b0ac49313873a0e0b982c591a5264 | — | 2026-03-18 | |
| FileHash-MD5 | 3288c284561055044c489567fd630ac2 | — | 2026-03-18 | |
| FileHash-MD5 | 461ade40b800ae80a40985594e1ac236 | — | 2026-03-18 | |
| FileHash-MD5 | 61f65bd593ea0e52ac0dfdc6bc9cd73a | — | 2026-03-18 | |
| FileHash-MD5 | 7dc50e8af0070e544bff5299405cd3b9 | — | 2026-03-18 | |
| FileHash-SHA1 | 11ffeabbe42159e1365aa82463d8690c845ce7b7 | SHA1 of 3288c284561055044c489567fd630ac2 | 2026-03-18 | |
| FileHash-SHA1 | b3892eef846c044a2b0785d54a432b3e93a968c8 | SHA1 of 461ade40b800ae80a40985594e1ac236 | 2026-03-18 | |
| FileHash-SHA1 | e5adeecfb03cc7d26de2f11746d3aef6b1fd4830 | SHA1 of 61f65bd593ea0e52ac0dfdc6bc9cd73a | 2026-03-18 | |
| FileHash-SHA256 | 798af20db39280f90a1d35f2ac2c1d62124d1f5218a2a0fa29d87a13340bd3e4 | SHA256 of 461ade40b800ae80a40985594e1ac236 | 2026-03-18 | |
| FileHash-SHA256 | aa51573f9abcd4a1ec4a61ee7e5811c0279e015ea22bdb787780d67ce7153a57 | SHA256 of 61f65bd593ea0e52ac0dfdc6bc9cd73a | 2026-03-18 | |
| FileHash-SHA256 | ac92d4c6397eb4451095949ac485ef4ec38501d7bb6f475419529ae67e297753 | SHA256 of 3288c284561055044c489567fd630ac2 | 2026-03-18 | |
| domain | drfeysal.com | — | 2026-03-18 |