logo

KONNI Adopts AI to Generate PowerShell Backdoors

ID: 5ccc82df-ebfe-5691-b85b-f73566854049

STIX ID: report--5ccc82df-ebfe-5691-b85b-f73566854049

Feed Name: Check Point Research

Threat Score
88/100

Date Published: 2026-01-22

Date Updated: 2026-04-27

Author: [email protected]

...
...

Check Point Research documents a KONNI-linked multi-stage phishing campaign targeting blockchain developers across APAC that delivers weaponized LNKs and an AI-generated, heavily obfuscated PowerShell backdoor; the malware includes sandbox-evasion, UAC bypass, scheduled-task persistence, C2 token emulation, and optional RMM deployment, and the report provides extensive IOCs (file hashes, domains, and IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.