logo

North Korea ramps up cyberspying in Ukraine to assess war risk

ID: da69d159-cb61-54d2-b2eb-8bfdbc8c0270

STIX ID: report--da69d159-cb61-54d2-b2eb-8bfdbc8c0270

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-05-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Proofpoint observed North Korea–linked Konni (TA406) conducting targeted phishing campaigns against Ukrainian government entities to collect intelligence related to DPRK involvement and battlefield conditions; attackers use convincing think-tank lures and fake Microsoft alerts to deliver MEGA-hosted RAR/CHM archives or ZIP/LNK attachments that execute encoded PowerShell/VBScript and attempt persistence and credential harvesting, while the final espionage payload was not recovered but is assessed to be a backdoor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.