logo

Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

ID: d308f9c3-d1bf-564f-b0cd-feadd8cac01b

STIX ID: report--d308f9c3-d1bf-564f-b0cd-feadd8cac01b

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

South Korean firm Genians attributes a targeted multi-stage campaign to Konni (North Korean actors) that begins with spear-phishing ZIP attachments containing LNK shortcuts. Execution of the LNK fetches an AutoIt-based RAT (EndRAT/EndClient) and additional RATs (RftRAT, Remcos), establishes persistence via scheduled tasks, steals internal documents, and leverages the victim's KakaoTalk desktop to selectively distribute malicious ZIP payloads to the victim's contacts, turning compromised users into propagation vectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.