logo

Russian Ministry Software Backdoored with North Korean KONNI Malware

ID: 8c2c65aa-d110-5ad1-a401-42c8c9dffcb5

STIX ID: report--8c2c65aa-d110-5ad1-a401-42c8c9dffcb5

Feed Name: HackRead

Threat Score
85/100

Date Published: 2024-02-24

Date Updated: 2026-04-22

Author: Waqas

...
...

German firm DCSO identified a KONNI malware sample (uploaded to VirusTotal in Jan 2024) linked to DPRK-associated actors and targeting the Russian Ministry of Foreign Affairs by backdooring a Russian consular software installer (Statistika KZU). The report details KONNI's capabilities (MSI-based deployment, AES-CTR encrypted C2, HTTP comms, file upload/download, CAB compression), delivery via a compromised installer containing user manuals, and contextualizes the finding with previous KONNI campaigns and geopolitical ramifications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.