logo

Russian Government Software Backdoored to Deploy Konni RAT Malware

ID: 7380ecb4-5b65-5aed-ae51-96bace80ddb2

STIX ID: report--7380ecb4-5b65-5aed-ae51-96bace80ddb2

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-02-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

DCSO identified a trojanized MSI installer for a Russian Ministry of Foreign Affairs consular tool ('Statistika KZU') that delivers Konni RAT (aka UpDog). The implant provides remote access, file transfer, and command execution; packaging within legitimate installers is a recurring TTP linked to DPRK-associated Konni/TA406 activity targeting Russian entities, indicating active, targeted espionage against consular systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.