Konni hackers target blockchain engineers with AI-built malware
ID: 87f09208-78ac-507a-82ea-1d36acb93b31
STIX ID: report--87f09208-78ac-507a-82ea-1d36acb93b31
Feed Name: Bleeping Computer
Threat Score
Konni (Opal Sleet/TA406), a North Korean-linked APT, is targeting blockchain developers in the Asia-Pacific region using Discord-hosted lures that deliver a multi-stage infection chain (LNK -> PowerShell loader -> DOCX/CAB -> PowerShell backdoor); the backdoor appears AI-assisted, employs evasion and privilege-based behaviors, uses scheduled tasks for persistence, communicates with C2 for remote commands, and researchers have published IoCs to aid defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
