home.social

#konni — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #konni, aggregated by home.social.

fetched live
  1. Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware

    North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.

    Pulse ID: 6ab51a43ec94931b637c0607
    Pulse Link: otx.alienvault.com/pulse/6ab51
    Pulse Author: AlienVault
    Created: 2026-09-24 12:40:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #LNK #PowerShell #Ukraine #Konni #OTX #AlienVault

  2. Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware

    North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.

    Pulse ID: 6ab51a43ec94931b637c0607
    Pulse Link: otx.alienvault.com/pulse/6ab51
    Pulse Author: AlienVault
    Created: 2026-09-24 12:40:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #LNK #PowerShell #Ukraine #Konni #OTX #AlienVault

  3. Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware

    North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.

    Pulse ID: 6ab51a43ec94931b637c0607
    Pulse Link: otx.alienvault.com/pulse/6ab51
    Pulse Author: AlienVault
    Created: 2026-09-24 12:40:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #LNK #PowerShell #Ukraine #Konni #OTX #AlienVault

  4. Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware

    North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.

    Pulse ID: 6ab51a43ec94931b637c0607
    Pulse Link: otx.alienvault.com/pulse/6ab51
    Pulse Author: AlienVault
    Created: 2026-09-24 12:40:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #LNK #PowerShell #Ukraine #Konni #OTX #AlienVault

  5. "Public meetings are not press conferences!" CM Pinarayi Vijayan doubles down on his "Go ask that at home" comment, stating that 'natural reactions' follow when public decorum is ignored. Addressing the Konni incident from Idukki, the CM dismissed criticisms regarding his composure and reminded the audience that those uninterested in the speech are free to leave. english.mathrubhumi.com/news/k #PinarayiVijayan #KeralaPolitics #LDF2026 #Konni #KeralaElections

  6. "Public meetings are not press conferences!" CM Pinarayi Vijayan doubles down on his "Go ask that at home" comment, stating that 'natural reactions' follow when public decorum is ignored. Addressing the Konni incident from Idukki, the CM dismissed criticisms regarding his composure and reminded the audience that those uninterested in the speech are free to leave. english.mathrubhumi.com/news/k #PinarayiVijayan #KeralaPolitics #LDF2026 #Konni #KeralaElections

  7. #CheckPoint Research identified an ongoing #phishing campaign associated with #KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated #PowerShell #backdoors.

    research.checkpoint.com/2026/k

  8. #CheckPoint Research identified an ongoing #phishing campaign associated with #KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated #PowerShell #backdoors.

    research.checkpoint.com/2026/k

  9. #CheckPoint Research identified an ongoing #phishing campaign associated with #KONNI, a North Korean–linked threat actor active since at least 2014. The campaign targets software developers and engineering teams across the Asia-Pacific region, including Japan, Australia, and India, using blockchain-themed lures to prompt interaction and deliver malicious content. In observed activity, the threat actor deploys AI-generated #PowerShell #backdoors.

    research.checkpoint.com/2026/k

  10. 📰 North Korean 'Konni' APT Weaponizes Google Ads to Deliver EndRAT Malware

    North Korean APT 'Konni' is weaponizing Google Ads URLs in 'Operation Poseidon' to bypass security and deliver the EndRAT malware. The attack uses clever evasion techniques to beat AI filters. ⚠️ #Konni #APT #Malware #EndRAT #ThreatIntel

    🔗 cyber.netsecops.io/articles/no

  11. 🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.

    Read: hackread.com/hackers-kakaotalk

    #CyberSecurity #NorthKorea #SouthKorea #Spyware #KakaoTalk

  12. 🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.

    Read: hackread.com/hackers-kakaotalk

    #CyberSecurity #NorthKorea #SouthKorea #Spyware #KakaoTalk

  13. 🪝 North Korea-linked #KONNI hackers used KakaoTalk and Google Find Hub to spy on victims and remotely wipe #Android devices in a targeted phishing campaign.

    Read: hackread.com/hackers-kakaotalk

    #CyberSecurity #NorthKorea #SouthKorea #Spyware #KakaoTalk

  14. 🔎 In a recent analysis, the @FortiGuardLabs team revealed that when enabled, the #Konni #malware campaign facilitates the deployment of a DLL file, embedding information gathering, and exfiltration capabilities. 🥷

    Learn more ➡️ securityboulevard.com/2023/12/ via Security Boulevard

    #cti #cybersecurity #threatintelligence

  15. #APT #Konni

    ZIP File: e809ed9c83ee468369e665259fb1ae7b

    LNK File: d1dc2db2956803de7eef7a76a6ac5cb2
    주요도시 시장가격 조사2023.lnk

    ZIP->LNK->BAT->Powershell

    hxxps://dl.dropboxusercontent.com/scl/fi/h7p5aearkbq6rnb2oh633/20231028_selca.zip?rlkey=8gmnnfrezz2vnndsr1cz781cv&dl=0