logo

Konni (Vedalia / TA406 / Opal Sleet): North Korea’s Steady Hand in Espionage Operations

ID: b742df3a-43c1-53e8-a6e6-7c122ba2aecb

STIX ID: report--b742df3a-43c1-53e8-a6e6-7c122ba2aecb

Feed Name: Brandefense Blog

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-27

Author: BRANDEFENSE

...
...

Konni (Vedalia/TA406/Opal Sleet) is a North Korean state-aligned APT conducting persistent, intelligence-driven cyber-espionage against government, defense, and diplomatic targets; the report details spearphishing initial access (weaponized Office/RTF/LNK), PowerShell/VBScript/JS loaders, a small malware ecosystem (KONNI RAT, CARROTBAT, BabyShark), C2 using legitimate hosting/compromised servers, campaign history from 2017–2025, and recommended mitigations such as advanced email filtering, IOC monitoring, behavioral detection, and MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.