logo

Blackgear__2018__unit42-comnie-continues-target-organizations-east-asia.pdf

ID: e745086d-c399-4822-bf92-da14b0965cd3

STIX ID: report--e745086d-c399-4822-bf92-da14b0965cd3

Threat Score

72/100

Uploaded: 2026-08-14

Published Date: 2018-02-01

Last Modified Date: 2018-02-01

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes Comnie, a long-running remote backdoor used in targeted espionage against Taiwanese and South Korean organizations; attackers deliver it via malicious Office macros that show decoy documents, retrieve obfuscated C2 data from legitimate third-party services (GitHub/Tumblr/Blogspot), use RC4 for obfuscation and network traffic, achieve persistence via LNK/DLL techniques, and the report includes technical details, scripts, and IoCs for detection and mitigation.