North Korean threat actors associated with the KONNI APT group have been observed leveraging Google's Find Hub (formerly Find My Device) to remotely wipe and track Android devices, primarily targeting South Korean individuals. The attackers initiate contact through spear-phishing campaigns, often impersonating trusted entities such as the National Tax Service or psychological counselors, and distribute malware via malicious attachments or links. Once a device is compromised, the attackers use Google Find Hub's legitimate management features to reset devices to factory settings, erasing personal data and disrupting communications, particularly by disconnecting victims from KakaoTalk sessions. This tactic not only hinders incident response and recovery but also enables the attackers to hijack messaging accounts and propagate further attacks to the victim's contacts.
Technical analysis reveals that the infection chain involves digitally signed MSI installers, BAT and VBS scripts for persistence, and the deployment of remote access trojans such as RemcosRAT, QuasarRAT, and Lilith RAT. The attackers maintain long-term access to compromised systems, conduct internal reconnaissance, and exfiltrate sensitive data. The campaign demonstrates a novel abuse of legitimate device management tools for destructive purposes and highlights the evolving sophistication of North Korean cyber operations targeting both Android and Windows platforms in South Korea.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers at Genians Security Center disclosed the campaign, attributing it to the North Korea-linked Konni cluster and documenting its use of KakaoTalk, credential theft, RAT deployment, and Google Find Hub abuse. The report included indicators of compromise and mitigation guidance for defenders.
After taking over victims' Google accounts, the attackers used Google's Find Hub/Find My Device service to locate Android devices and trigger unauthorized factory resets. The tactic erased data, destroyed evidence of compromise, and was described as the first known state-sponsored abuse of the feature for destructive wiping.
After initial compromise, the attackers harvested sensitive information such as personal data, credentials, and in some cases webcam data. They also abused victims' still-accessible KakaoTalk accounts and trusted relationships to send malware to additional contacts, expanding the intrusion.
During the campaign, victims received malicious MSI installers and other lures through spear-phishing emails and KakaoTalk messages. The malware chain deployed RATs including RemcosRAT, QuasarRAT, LilithRAT, and related tooling to establish surveillance and steal credentials.
In September 2025, the North Korea-linked Konni group launched a campaign targeting individuals in South Korea, including people connected to North Korean defectors. The operation relied on social engineering and impersonation of trusted figures such as psychological counselors, human-rights activists, and tax officials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
8 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcego.theregister.com
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourcecsoonline.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.