Konni (Vedalia / TA406 / Opal Sleet): North Korea’s Steady Hand in Espionage Operations
ID: b742df3a-43c1-53e8-a6e6-7c122ba2aecb
STIX ID: report--b742df3a-43c1-53e8-a6e6-7c122ba2aecb
Feed Name: Brandefense Blog
Konni (Vedalia/TA406/Opal Sleet) is a North Korean state-aligned APT conducting persistent, intelligence-driven cyber-espionage against government, defense, and diplomatic targets; the report details spearphishing initial access (weaponized Office/RTF/LNK), PowerShell/VBScript/JS loaders, a small malware ecosystem (KONNI RAT, CARROTBAT, BabyShark), C2 using legitimate hosting/compromised servers, campaign history from 2017–2025, and recommended mitigations such as advanced email filtering, IOC monitoring, behavioral detection, and MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
