Russian Government Software Backdoored to Deploy Konni RAT Malware
ID: 7380ecb4-5b65-5aed-ae51-96bace80ddb2
STIX ID: report--7380ecb4-5b65-5aed-ae51-96bace80ddb2
Feed Name: The Hacker News
Threat Score
DCSO identified a trojanized MSI installer for a Russian Ministry of Foreign Affairs consular tool ('Statistika KZU') that delivers Konni RAT (aka UpDog). The implant provides remote access, file transfer, and command execution; packaging within legitimate installers is a recurring TTP linked to DPRK-associated Konni/TA406 activity targeting Russian entities, indicating active, targeted espionage against consular systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
