logo

Konni Hijacks KakaoTalk Accounts in Spear-Phishing Malware Campaign

ID: 6697c49c-87d4-5c77-8378-49bfafac2f1e

STIX ID: report--6697c49c-87d4-5c77-8378-49bfafac2f1e

Feed Name: GBHackers

Threat Score
86/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Konni APT conducted a sophisticated multi-stage campaign that began with targeted spear‑phishing using malicious LNK shortcuts which executed PowerShell droppers and AutoIt-based loaders to install multiple RATs (EndRAT, RftRAT, RemcosRAT). The operator maintained long-term persistence, exfiltrated internal documents and account data, and hijacked KakaoTalk PC sessions to propagate malicious archives to contacts; the report includes detailed TTPs and IoCs (file hashes, domain drfeysal.com, and C2 IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.