logo

Konni hackers target blockchain engineers with AI-built malware

ID: 87f09208-78ac-507a-82ea-1d36acb93b31

STIX ID: report--87f09208-78ac-507a-82ea-1d36acb93b31

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-24

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Konni (Opal Sleet/TA406), a North Korean-linked APT, is targeting blockchain developers in the Asia-Pacific region using Discord-hosted lures that deliver a multi-stage infection chain (LNK -> PowerShell loader -> DOCX/CAB -> PowerShell backdoor); the backdoor appears AI-assisted, employs evasion and privilege-based behaviors, uses scheduled tasks for persistence, communicates with C2 for remote commands, and researchers have published IoCs to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.