Konni APT Hijacks KakaoTalk Accounts to Spread Malware in Multi-Stage Spear-Phishing Campaign
ID: 2ef7d934-173e-56a5-96f5-394fec671237
STIX ID: report--2ef7d934-173e-56a5-96f5-394fec671237
Feed Name: cybersecurityNews.com
Threat Score
Konni APT conducted a targeted spear-phishing campaign using archive attachments with malicious LNK shortcuts that silently launch a PowerShell loader to retrieve AutoIt-based RATs. The intruder maintained long dwell time to collect documents and account data, hijacked the KakaoTalk PC application to distribute malicious files to contacts, and established persistent access via scheduled tasks and geographically distributed C2 servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
