Konni RAT Exploit Windows Explorer Limitations To Steal Data and Sent to Remote Server
ID: 0561f575-2a7d-50bf-8a09-839d2277b265
STIX ID: report--0561f575-2a7d-50bf-8a09-839d2277b265
Feed Name: Cyber Press
Konni RAT is a multi-stage Remote Access Trojan that abuses Windows Explorer behaviours (260-character LNK limits and hidden file extensions) to hide malicious LNK shortcuts which run obfuscated PowerShell, VBScript and batch scripts; these components collect and exfiltrate directory listings and system configuration to encrypted remote command-and-control servers while maintaining persistence and deleting traces. The report highlights the malware's obfuscation, dynamic URL generation, and stealthy file operations, and recommends advanced endpoint protection, network monitoring, domain blocking, software updates, user education, and incident response planning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
