KONNI Adopts AI to Generate PowerShell Backdoors
ID: 5ccc82df-ebfe-5691-b85b-f73566854049
STIX ID: report--5ccc82df-ebfe-5691-b85b-f73566854049
Feed Name: Check Point Research
Threat Score
Check Point Research documents a KONNI-linked multi-stage phishing campaign targeting blockchain developers across APAC that delivers weaponized LNKs and an AI-generated, heavily obfuscated PowerShell backdoor; the malware includes sandbox-evasion, UAC bypass, scheduled-task persistence, C2 token emulation, and optional RMM deployment, and the report provides extensive IOCs (file hashes, domains, and IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
