#konni — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #konni, aggregated by home.social.
-
SOCRadar uncovered the Konni Operation Conflict Compass campaign targeting Ukraine. Learn how Operation Conflict Compass uses fake PDFs and VelvetCake.
#OperationConflictCompass #Konni #VelvetCake #CyberSecurity #DPRK
-
SOCRadar uncovered the Konni Operation Conflict Compass campaign targeting Ukraine. Learn how Operation Conflict Compass uses fake PDFs and VelvetCake.
#OperationConflictCompass #Konni #VelvetCake #CyberSecurity #DPRK
-
SOCRadar uncovered the Konni Operation Conflict Compass campaign targeting Ukraine. Learn how Operation Conflict Compass uses fake PDFs and VelvetCake.
#OperationConflictCompass #Konni #VelvetCake #CyberSecurity #DPRK
-
Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware
North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.
Pulse ID: 6ab51a43ec94931b637c0607
Pulse Link: https://otx.alienvault.com/pulse/6ab51a43ec94931b637c0607
Pulse Author: AlienVault
Created: 2026-09-24 12:40:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware
North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.
Pulse ID: 6ab51a43ec94931b637c0607
Pulse Link: https://otx.alienvault.com/pulse/6ab51a43ec94931b637c0607
Pulse Author: AlienVault
Created: 2026-09-24 12:40:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware
North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.
Pulse ID: 6ab51a43ec94931b637c0607
Pulse Link: https://otx.alienvault.com/pulse/6ab51a43ec94931b637c0607
Pulse Author: AlienVault
Created: 2026-09-24 12:40:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware
North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.
Pulse ID: 6ab51a43ec94931b637c0607
Pulse Link: https://otx.alienvault.com/pulse/6ab51a43ec94931b637c0607
Pulse Author: AlienVault
Created: 2026-09-24 12:40:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
-
"Public meetings are not press conferences!" CM Pinarayi Vijayan doubles down on his "Go ask that at home" comment, stating that 'natural reactions' follow when public decorum is ignored. Addressing the Konni incident from Idukki, the CM dismissed criticisms regarding his composure and reminded the audience that those uninterested in the speech are free to leave. https://english.mathrubhumi.com/news/kerala/go-ask-that-at-home-a-natural-reaction-public-meetings-have-decorum-kerala-cm-pinarayi-vijayan-watch-hi4cs1jf?utm_source=dlvr.it&utm_medium=mastodon #PinarayiVijayan #KeralaPolitics #LDF2026 #Konni #KeralaElections
-
"Public meetings are not press conferences!" CM Pinarayi Vijayan doubles down on his "Go ask that at home" comment, stating that 'natural reactions' follow when public decorum is ignored. Addressing the Konni incident from Idukki, the CM dismissed criticisms regarding his composure and reminded the audience that those uninterested in the speech are free to leave. https://english.mathrubhumi.com/news/kerala/go-ask-that-at-home-a-natural-reaction-public-meetings-have-decorum-kerala-cm-pinarayi-vijayan-watch-hi4cs1jf?utm_source=dlvr.it&utm_medium=mastodon #PinarayiVijayan #KeralaPolitics #LDF2026 #Konni #KeralaElections
-
#CheckPoint Research identified an ongoing #phishing campaign associated with #KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated #PowerShell #backdoors.
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/
-
#CheckPoint Research identified an ongoing #phishing campaign associated with #KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated #PowerShell #backdoors.
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/
-
#CheckPoint Research identified an ongoing #phishing campaign associated with #KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated #PowerShell #backdoors.
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/
-
KONNI Adopts AI to Generate PowerShell Backdoors
#Konni
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/ -
KONNI Adopts AI to Generate PowerShell Backdoors
#Konni
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/ -
KONNI Adopts AI to Generate PowerShell Backdoors
#Konni
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/ -
KONNI Adopts AI to Generate PowerShell Backdoors
#Konni
https://research.checkpoint.com/2026/konni-targets-developers-with-ai-malware/ -
📰 North Korean 'Konni' APT Weaponizes Google Ads to Deliver EndRAT Malware
North Korean APT 'Konni' is weaponizing Google Ads URLs in 'Operation Poseidon' to bypass security and deliver the EndRAT malware. The attack uses clever evasion techniques to beat AI filters. ⚠️ #Konni #APT #Malware #EndRAT #ThreatIntel
-
Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/ #ScamsandFraud #Cybersecurity #GoogleFundHub #CyberAttack #NorthKorea #SouthKorea #KakaoTalk #Security #Android #Malware #Kimsuky #APT37 #Konni
-
Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/ #ScamsandFraud #Cybersecurity #GoogleFundHub #CyberAttack #NorthKorea #SouthKorea #KakaoTalk #Security #Android #Malware #Kimsuky #APT37 #Konni
-
Hackers Use KakaoTalk and Google Find Hub in Android Spyware Attack https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/ #ScamsandFraud #Cybersecurity #GoogleFundHub #CyberAttack #NorthKorea #SouthKorea #KakaoTalk #Security #Android #Malware #Kimsuky #APT37 #Konni
-
🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.
Read: https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/
-
🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.
Read: https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/
-
🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.
Read: https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/
-
🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.
Read: https://hackread.com/hackers-kakaotalk-google-find-hub-android-spyware/
-
State-Sponsored Remote Wipe Tactics Targeting Android Devices
#Konni
https://www.genians.co.kr/en/blog/threat_intelligence/android -
State-Sponsored Remote Wipe Tactics Targeting Android Devices
#Konni
https://www.genians.co.kr/en/blog/threat_intelligence/android -
State-Sponsored Remote Wipe Tactics Targeting Android Devices
#Konni
https://www.genians.co.kr/en/blog/threat_intelligence/android -
State-Sponsored Remote Wipe Tactics Targeting Android Devices
#Konni
https://www.genians.co.kr/en/blog/threat_intelligence/android -
North Korean hackers are using Google’s own tools to remotely wipe Android devices and hijack messaging apps. Think your account is safe? Dive into how a single breach can trigger a digital meltdown.
#konni
#apt37
#cyberespionage
#androidsecurity
#googlefindhub
#malware
#northkorea
#spearphishing
#infosec -
North Korean hackers are using Google’s own tools to remotely wipe Android devices and hijack messaging apps. Think your account is safe? Dive into how a single breach can trigger a digital meltdown.
#konni
#apt37
#cyberespionage
#androidsecurity
#googlefindhub
#malware
#northkorea
#spearphishing
#infosec -
North Korean hackers are using Google’s own tools to remotely wipe Android devices and hijack messaging apps. Think your account is safe? Dive into how a single breach can trigger a digital meltdown.
#konni
#apt37
#cyberespionage
#androidsecurity
#googlefindhub
#malware
#northkorea
#spearphishing
#infosec -
North Korean hackers are using Google’s own tools to remotely wipe Android devices and hijack messaging apps. Think your account is safe? Dive into how a single breach can trigger a digital meltdown.
#konni
#apt37
#cyberespionage
#androidsecurity
#googlefindhub
#malware
#northkorea
#spearphishing
#infosec -
Russian Ministry Software Backdoored with North Korean KONNI Malware https://www.hackread.com/russia-software-backdoor-n-korea-konni-malware/ #CyberAttack #NorthKorea #Security #backdoor #Malware #Russia #Konni #News
-
🔎 In a recent analysis, the @FortiGuardLabs team revealed that when enabled, the #Konni #malware campaign facilitates the deployment of a DLL file, embedding information gathering, and exfiltration capabilities. 🥷
Learn more ➡️ https://securityboulevard.com/2023/12/konni-malware-alert-uncovering-the-russian-language-threat/ via Security Boulevard
-
Konni is recognized for its focus on Russia, employing spear-phishing emails and malicious documents as entry points for its cyberattacks.
-
After activation, the malware determines whether the device is running on a 64-bit or 32-bit operating system.
#Cybersecurity #NorthKorea #Konni #Lazarus
https://cybersec84.wordpress.com/2023/09/19/konni-aims-to-be-the-next-lazarus/
-
North Korean hackers likely behind barrage of cyberattacks against journalists - https://www.nknews.org/2021/10/north-korean-hackers-likely-behind-barrage-of-cyberattacks-against-journalists/ #dprk #malware #kimsuky #konni