logo

Konni APT Hijacks KakaoTalk Accounts to Spread Malware in Multi-Stage Spear-Phishing Campaign

ID: 2ef7d934-173e-56a5-96f5-394fec671237

STIX ID: report--2ef7d934-173e-56a5-96f5-394fec671237

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Konni APT conducted a targeted spear-phishing campaign using archive attachments with malicious LNK shortcuts that silently launch a PowerShell loader to retrieve AutoIt-based RATs. The intruder maintained long dwell time to collect documents and account data, hijacked the KakaoTalk PC application to distribute malicious files to contacts, and established persistent access via scheduled tasks and geographically distributed C2 servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.