logo

Konni RAT Resurfaces: North Korean Espionage Malware Evolves with Stealth and Persistence

ID: 1e033cb1-cf27-5157-b333-530eaae53a77

STIX ID: report--1e033cb1-cf27-5157-b333-530eaae53a77

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: do son

...
...

Cyfirma’s analysis details Konni RAT, a sophisticated Windows Remote Access Trojan that employs a multi-stage infection chain (malicious .lnk, PowerShell, VBScript, batch files, and a CAB payload) to collect system information and user files, exfiltrate them to a C2 server (roofcolor.com), and maintain persistence via registry Run keys while erasing traces; the report attributes usage to APT37 and links the tool to espionage campaigns targeting government entities including the Russian Ministry of Foreign Affairs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.