A threat group known as Konni APT has been caught running a multi-stage attack campaign that starts with targeted spear-phishing emails and ends with hijacking victims’ KakaoTalk messaging accounts to push malware further.
The campaign was uncovered following a forensic investigation of a compromised system and relies on North Korean human rights themes to trick targets into opening files that appear completely harmless.
The attack started with emails crafted to look like official notices appointing recipients as North Korean human rights lecturers. These messages were designed to feel relevant to the target’s professional interests, making them appear credible.
Inside the email was an archive containing a malicious LNK shortcut file disguised with a standard document icon.
When the recipient clicked on it, the file quietly launched a PowerShell script in the background, which connected to an external command-and-control server and downloaded additional malware onto the victim’s machine.
Genians analysts identified that after gaining an initial foothold, the threat actor did not pull back.
Instead, the attacker remained hidden on the infected system for an extended period, quietly collecting internal documents, user account details, and system environment data.
This prolonged dwell time gave the group ample opportunity to gather meaningful intelligence before escalating the attack.
What separates this campaign from a typical phishing operation is what came next. The attacker gained unauthorized access to the victim’s KakaoTalk PC application, which was already running on the infected machine.
Using the victim’s own contact list, the attacker carefully selected specific friends and sent them a malicious file disguised as a planning document for North Korea-related video content.
This turned the original victim into a trusted delivery point for malware, making the secondary wave of attacks significantly harder for recipients to detect.
The full campaign also involved the deployment of three separate remote access tools — EndRAT, RftRAT, and RemcosRAT — all delivered as AutoIt-based scripts disguised as document files.
C2 servers connected to the operation were traced to locations in Finland, Japan, and the Netherlands, suggesting a deliberate effort to spread the infrastructure across multiple borders.
The malicious LNK file at the heart of this attack is far more capable than a typical shortcut. When a user double-clicks the file, it silently launches a 32-bit PowerShell process through cmd.exe, specifically using the SysWOW64 directory path — a technique that can sidestep certain security controls.
Rather than using a hardcoded filename, the PowerShell script locates the LNK file by matching a specific file size, meaning it continues to function even if renamed.
Once located, the script reads a large data block embedded within the LNK file from a fixed offset and decodes it using a single-byte XOR key. The decoded result is a decoy PDF that opens for the user, making the interaction appear completely normal.
While the victim reads the decoy, the actual attack continues in the background. The LNK file deletes itself from disk immediately after execution, removing forensic evidence and making it difficult to trace the incident.
Two files are then downloaded from the C2 domain — a legitimate AutoIt interpreter and a compiled malicious AutoIt script. A scheduled task is created to run every minute for 365 days, giving the attacker reliable and long-lasting access to the infected machine.
To reduce exposure to this threat, organizations and individuals should consider the following:
Follow us on Google News, LinkedIn, and X to Get More Instant Updates, Set CSN as a Preferred Source in Google.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…