Konni is a North Korea-aligned threat actor associated with long-running espionage operations and, more recently, financially motivated targeting of the cryptocurrency ecosystem. Known aliases include Earth Imp, Konni APT, Konni Group, Opal Sleet, Osmium, PlaneDown, and TA406. Reporting in the provided material consistently places the actor within the DPRK threat landscape and describes sustained operations against South Korean individuals and organizations, diplomatic and policy targets, software developers, engineering teams, and cryptocurrency professionals. Konni has historically relied on spearphishing and socially engineered lures tied to Korean political, governmental, tax, diplomatic, financial, and human-rights themes. The actor has repeatedly used malicious shortcut files, archive attachments, decoy documents, PowerShell, AutoIt-based loaders, and staged payload delivery. Observed tradecraft includes abuse of oversized or whitespace-padded LNK files for evasion, scheduled-task and startup-based persistence, credential theft, reconnaissance, long-term remote access, and exfiltration of documents and host data. Campaigns also showed anti-forensics behavior such as deleting initial artifacts and, in Android-related intrusions, abusing Google Find Hub / Find My Device functionality to remotely wipe compromised devices and erase evidence. The actor operates a diverse malware ecosystem. Families and components linked in the supplied facts include EndRAT, RftRAT, RemcosRAT, QuasarRAT, GSRAT, EggShell variants, and FileRATClient. EndRAT and related AutoIt-based tooling have been used in multi-stage Windows intrusions that establish persistence, provide shell access, transfer files, and support secondary propagation through hijacked KakaoTalk sessions. More recent reporting also describes AI-assisted malware development in Konni-associated PowerShell backdoors. A notable evolution is Konni’s expansion from primarily Windows-focused espionage into macOS targeting and cryptocurrency-focused operations. Beginning in late 2025, the actor was observed targeting crypto industry professionals with lures themed around OTC trades, token transfers, and Web3 payment workflows. In that campaign, compiled AppleScript bundles masquerading as office documents harvested local credentials, abused macOS privacy controls, established LaunchAgent persistence, performed host reconnaissance, and deployed final-stage implants including FileRATClient and an EggShell variant. FileRATClient was described as a modular cross-platform remote access trojan supporting keylogging, screen capture, webcam access, browser hijacking, proxying, remote command execution, and self-destruct functionality. Konni has also been linked to opportunistic exploitation of newly disclosed vulnerabilities in targeted delivery chains. The supplied facts associate TA406 / Opal Sleet with campaigns chaining Microsoft Office and Windows Shell vulnerabilities in 2026, using RTF and embedded LNK-based sequences to retrieve and execute follow-on payloads. Victimology in the supplied material centers most strongly on South Korea, but also includes confirmed or reported targeting in the United States, United Kingdom, Russia, Japan, and other countries. Sector targeting spans government and public-sector entities, finance and cryptocurrency-related organizations, software and engineering teams, and in some cases defense- or diplomacy-adjacent targets. Overall, Konni is best characterized as a DPRK espionage actor that increasingly blends surveillance, credential theft, persistence, and data collection with financially motivated cryptocurrency targeting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 malware families attributed to this actor across reporting.
15 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
DPRK aligned TA406 (Opal Sleet) chained CVE-2026-21510 with CVE-2026-21509 in active campaigns.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a DPRK espionage actor in the context of activity targeting cryptocurrency.
North Korean threat actor observed exploiting ZDI-CAN-25373 using oversized malicious .lnk files with extensive whitespace and junk content for evasion.
Referenced as an example of a DPRK-aligned threat actor opportunistically exploiting public proof-of-concept code for network-facing vulnerabilities in 2026; not specifically tied to exploitation of CVE-2026-42055 in this content.
Mentioned only as one of several threat actors active in 2026.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.