logo

North Korea–linked KONNI uses AI to build stealthy malware tooling

ID: 7327510b-315a-5e40-b9ad-84f4826afd3b

STIX ID: report--7327510b-315a-5e40-b9ad-84f4826afd3b

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-01-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Executive summary:** Check Point Research attributes an active phishing campaign to North Korea–linked KONNI that targets developers (notably in blockchain/crypto projects) using Discord-hosted ZIPs containing a PDF and a weaponized LNK which launches an embedded PowerShell loader; the campaign deploys an AI-like, heavily obfuscated in-memory PowerShell backdoor with persistence via scheduled tasks, UAC and Defender evasion, host fingerprinting for C2, and the ability to install legitimate RMM tools for long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.