logo

Konni RAT Exploit Windows Explorer Limitations To Steal Data and Sent to Remote Server

ID: 0561f575-2a7d-50bf-8a09-839d2277b265

STIX ID: report--0561f575-2a7d-50bf-8a09-839d2277b265

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2025-03-31

Date Updated: 2026-04-13

Author: Mandvi

...
...

Konni RAT is a multi-stage Remote Access Trojan that abuses Windows Explorer behaviours (260-character LNK limits and hidden file extensions) to hide malicious LNK shortcuts which run obfuscated PowerShell, VBScript and batch scripts; these components collect and exfiltrate directory listings and system configuration to encrypted remote command-and-control servers while maintaining persistence and deleting traces. The report highlights the malware's obfuscation, dynamic URL generation, and stealthy file operations, and recommends advanced endpoint protection, network monitoring, domain blocking, software updates, user education, and incident response planning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.