Lovers' Spat? North Korea Backdoors Russian Foreign Affairs Ministry
ID: fd1ae921-d9e3-5b6b-a109-f1457bbe83cb
STIX ID: report--fd1ae921-d9e3-5b6b-a109-f1457bbe83cb
Feed Name: Dark Reading
Threat Score
A Konni backdoor sample, linked to North Korean state-aligned actors, was uploaded to VirusTotal after being found bundled inside a Russian-language installer for "Statistika KZU," a tool likely used internally by Russia's Ministry of Foreign Affairs; researchers from DCSO CyTec assessed the installer and concluded it appears to be a targeted supply-side backdoor aimed at Russian diplomatic systems, continuing a history of Konni activity against Russian targets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
