DPRK's Konni Targets Blockchain Developers With AI-Generated Backdoor
ID: 27840d82-eb87-5bcc-959d-05302231792a
STIX ID: report--27840d82-eb87-5bcc-959d-05302231792a
Feed Name: Dark Reading
Threat Score
Date Published: 2026-01-26
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
...
...
Konni, a DPRK-linked APT, is running a phishing campaign aimed at blockchain developers in APAC using convincing project documentation and an AI-written PowerShell backdoor to establish persistence and harvest development infrastructure, credentials, and cryptocurrency access; Check Point provides analysis and IoCs indicating a notable shift in targeting and tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
