North Korea–linked KONNI uses AI to build stealthy malware tooling
ID: 7327510b-315a-5e40-b9ad-84f4826afd3b
STIX ID: report--7327510b-315a-5e40-b9ad-84f4826afd3b
Feed Name: Security Affairs
**Executive summary:** Check Point Research attributes an active phishing campaign to North Korea–linked KONNI that targets developers (notably in blockchain/crypto projects) using Discord-hosted ZIPs containing a PDF and a weaponized LNK which launches an embedded PowerShell loader; the campaign deploys an AI-like, heavily obfuscated in-memory PowerShell backdoor with persistence via scheduled tasks, UAC and Defender evasion, host fingerprinting for C2, and the ability to install legitimate RMM tools for long-term access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
