puNK-003 — APT Profile
puNK-003 is the designation used by South Korean vendor S2W's TALON team for a partially unidentified North Korea-linked activity cluster, first surfaced through VirusTotal threat hunting on 24 April 2024. The campaign delivered CURKON, an LNK downloader disguised as a Korean-language list of explanatory materials relating to a tax-evasion report, which displayed a decoy document while retrieving a legitimate AutoIt3 interpreter and a malicious AutoIt script from a hardcoded server; that script is a port of the open-source C++ Lilith RAT and gives the operators a reverse shell for arbitrary command execution. S2W assesses only a partial relationship to the KONNI group, based on shared AutoIt implementation and obfuscation, while noting that CURKON's LNK acts as a downloader rather than KONNI's dropper and that the VBS and BAT stages typical of KONNI are absent — the two are not established as the same actor. Symantec's protection bulletin coverage likewise describes the activity as North Korean, and no public reporting attributes financially motivated or hacktivist operations to this cluster.Also tracked as
KONNI (assessed overlap, not confirmed identity)
Tools & malware
- AutoIt Scripting/living-off-the-land (malicious AutoIt scripts run via legitimate AutoIt3.exe)
- CURKON LNK downloader
- Lilith RAT Remote Access Trojan (open-source C++, ported to AutoIt)