Blackgear__2018__unit42-comnie-continues-target-organizations-east-asia.pdf
ID: e745086d-c399-4822-bf92-da14b0965cd3
STIX ID: report--e745086d-c399-4822-bf92-da14b0965cd3
Threat Score
72/100
Uploaded: 2026-08-14
Published Date: 2018-02-01
Last Modified Date: 2018-02-01
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes Comnie, a long-running remote backdoor used in targeted espionage against Taiwanese and South Korean organizations; attackers deliver it via malicious Office macros that show decoy documents, retrieve obfuscated C2 data from legitimate third-party services (GitHub/Tumblr/Blogspot), use RC4 for obfuscation and network traffic, achieve persistence via LNK/DLL techniques, and the report includes technical details, scripts, and IoCs for detection and mitigation.
