KONNI, a North Korea–aligned threat actor active since at least 2014, has been linked to an ongoing phishing campaign targeting software developers and engineering teams with access to blockchain/crypto resources across the Asia-Pacific region, including Japan, Australia, and India. The operation uses convincing project documentation (e.g., detailed requirement papers and product briefs describing trading bots, credential systems, and delivery roadmaps) to build trust with technical staff and increase the likelihood of execution.
The infection chain uses PDF-themed lures delivered alongside malicious Windows shortcut (.lnk) files (often inside ZIP archives) that trigger an embedded PowerShell loader, ultimately deploying an AI-written PowerShell backdoor. Reporting notes the backdoor is unusually “developer-like” (clean structure and extensive comments) and includes capabilities such as host reconnaissance (hardware/system details), anti-analysis checks (e.g., debugging tool detection), and single-instance execution controls—raising the risk of follow-on compromise of source code repositories, cloud consoles, signing keys, and build/CI pipelines if developer endpoints are breached.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Check Point Research publicly reported the campaign, detailing a multi-stage infection chain using a malicious LNK, PowerShell loader, CAB archive, scheduled-task persistence, and an obfuscated in-memory backdoor. The researchers assessed the malware showed signs of AI-assisted generation and published indicators of compromise for defenders.
KONNI began an ongoing phishing operation targeting software developers and engineering teams tied to blockchain and cryptocurrency projects in Japan, Australia, and India. The campaign used fake project documentation and Discord-hosted ZIP archives to compromise development environments and access sensitive assets such as credentials, wallets, and infrastructure.
Earlier samples tied to the same KONNI tradecraft were observed on VirusTotal as an older multi-script variant, indicating the campaign or its precursor tooling was already in circulation by this time.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 41 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceresearch.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.