Opal_Sleet__2022__Konni_targeting_Russian_diplomatic_sector.pdf
ID: c91171e7-5179-4cbc-b2c8-bc39a909694b
STIX ID: report--c91171e7-5179-4cbc-b2c8-bc39a909694b
Threat Score
90/100
Uploaded: 2026-08-19
Published Date: 2022-01-03
Last Modified Date: 2022-01-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cluster25 analyzed a targeted Konni APT campaign that used New Year’s Eve-themed spear-phishing emails containing a .zip with a malicious screensaver executable (поздравление.scr). The downloader displays a decoy image, retrieves a base64-encoded CAB from atwebpages/c1.biz hosts, drops an installer that registers scrnsvc.dll (Konni RAT) as a Windows service, collects system data, archives it into a CAB, and exfiltrates it via HTTP to attacker-controlled C2 endpoints; the report provides sample hashes, C2 domains, ATT&CK mappings and high-confidence attribution to the North Korean group Konni.
