KONNI

S0356

Malware.View on attack.mitre.org

About this malware

KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014. KONNI has significant code overlap with the NOKKI malware family, and has been linked to several suspected North Korean campaigns targeting political organizations in Russia, East Asia, Europe and the Middle East; there is some evidence potentially linking KONNI to APT37.

Techniques used40

Procedure examples40

TechniqueProcedure example
T1005
Data from Local System

KONNI has stored collected information and discovered processes in a tmp file.

T1016
System Network Configuration Discovery

KONNI can collect the IP address from the victim’s machine.

T1027.002
Software Packing

KONNI has been packed for obfuscation.

T1027.013
Encrypted/Encoded File

KONNI is heavily obfuscated and includes encrypted configuration files.

T1033
System Owner/User Discovery

KONNI can collect the username from the victim’s machine.

T1036.004
Masquerade Task or Service

KONNI has pretended to be the xmlProv Network Provisioning service.

T1036.005
Match Legitimate Resource Name or Location

KONNI has created a shortcut called "Anti virus service.lnk" in an apparent attempt to masquerade as a legitimate file.

T1041
Exfiltration Over C2 Channel

KONNI has sent data and files to its C2 server.

T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol

KONNI has used FTP to exfiltrate reconnaissance data out.

T1049
System Network Connections Discovery

KONNI has used net session on the victim's machine.

T1056.001
Keylogging

KONNI has the capability to perform keylogging.

T1057
Process Discovery

KONNI has used the command cmd /c tasklist to get a snapshot of the current processes on the target machine.

T1059.001
PowerShell

KONNI used PowerShell to download and execute a specific 64-bit version of the malware.

T1059.003
Windows Command Shell

KONNI has used cmd.exe to execute arbitrary commands on the infected host across different stages of the infection chain.

T1059.007
JavaScript

KONNI has executed malicious JavaScript code.

View all 40 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Malwarebytes Konni Aug 2021 Open source
    Threat Intelligence Team. (2021, August 23). New variant of Konni malware used in campaign targetting Russia. Retrieved January 5, 2022.
  2. Medium KONNI Jan 2020 Open source
    Karmi, D. (2020, January 4). A Look Into Konni 2019 Campaign. Retrieved April 28, 2020.
  3. Talos Konni May 2017 Open source
    Rascagneres, P. (2017, May 03). KONNI: A Malware Under The Radar For Years. Retrieved November 5, 2018.
  4. Unit 42 NOKKI Sept 2018 Open source
    Grunzweig, J., Lee, B. (2018, September 27). New KONNI Malware attacking Eurasia and Southeast Asia. Retrieved November 5, 2018.
  5. Unit 42 Nokki Oct 2018 Open source
    Grunzweig, J. (2018, October 01). NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT. Retrieved November 5, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.