logo

Opal_Sleet__2022__Konni_targeting_Russian_diplomatic_sector.pdf

ID: c91171e7-5179-4cbc-b2c8-bc39a909694b

STIX ID: report--c91171e7-5179-4cbc-b2c8-bc39a909694b

Threat Score

90/100

Uploaded: 2026-08-19

Published Date: 2022-01-03

Last Modified Date: 2022-01-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cluster25 analyzed a targeted Konni APT campaign that used New Year’s Eve-themed spear-phishing emails containing a .zip with a malicious screensaver executable (поздравление.scr). The downloader displays a decoy image, retrieves a base64-encoded CAB from atwebpages/c1.biz hosts, drops an installer that registers scrnsvc.dll (Konni RAT) as a Windows service, collects system data, archives it into a CAB, and exfiltrates it via HTTP to attacker-controlled C2 endpoints; the report provides sample hashes, C2 domains, ATT&CK mappings and high-confidence attribution to the North Korean group Konni.