Hackers linked to North Korea used a compromised email account belonging to a staff member of Russia’s Ministry of Foreign Affairs to spear-phish Russian diplomatic targets, including the Russian embassy in Indonesia and Deputy Foreign Minister Sergey Alexeyevich Ryabkov. The operation, tracked by Cluster25 and Lumen Black Lotus Labs and attributed to the Konni/APT37 threat actor, used lures themed around New Year greetings and COVID-19 vaccination-status documents, along with spoofed Mail.ru and Yandex hostnames, to steal credentials and deliver Konni RAT.
The campaign fits a longer pattern of Konni activity documented over multiple years. Earlier research showed the malware evolving from an information stealer into a more capable remote access trojan with persistence, file transfer, command execution, and screenshot capture, typically spread through malicious email attachments and social engineering. Analysts have also reported newer Konni variants used in campaigns targeting Russia, reinforcing that the intrusion against Russian diplomatic entities was part of a sustained espionage effort built on reused malware, tailored decoys, and recurring focus on government and embassy-linked victims.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
Cluster25 published research in late December 2021 describing a phishing campaign targeting individuals in the Russian diplomatic apparatus and delivering Konni RAT. The report linked the activity to the Konni/APT37 threat actor.
In late December 2021, attackers used the compromised Russian Ministry of Foreign Affairs account mskhlystova@mid[.]ru to send phishing emails carrying a holiday-themed ZIP archive. Targets included staff at the Russian embassy in Indonesia and Deputy Foreign Minister Sergey Ryabkov, and the infection chain delivered Konni RAT disguised as scrnsvc.dll.
Around November 7, 2021, the attackers launched another campaign delivering links to an archive containing documents requesting vaccination-status information. The archive included an executable masquerading as legitimate COVID-19 vaccination-checking software that installed Konni.
A spear-phishing campaign against Russian diplomatic entities was active since at least October 19, 2021. Black Lotus Labs said the activity sought to harvest credentials for an active Russian Ministry of Foreign Affairs account.
Malwarebytes published research on a new KONNI malware variant used in a campaign targeting Russia. Black Lotus Labs later said a first-stage agent in the 2021 activity was nearly identical to one Malwarebytes had previously identified.
Cisco Talos analyzed four KONNI malware campaigns conducted in 2014, 2016, and twice in 2017, describing the malware’s evolution from an information stealer into a more capable RAT. The campaigns used malicious email attachments, decoy documents, and infrastructure hosted on free web hosting services.
Black Lotus Labs independently tracked related spear-phishing campaigns, confirmed Cluster25’s infection-chain findings, and identified reuse of IP address 152.89.247[.]26 across the October and December activity. It attributed the campaigns against Russian diplomatic entities to the North Korean Konni/APT37 threat actor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 20 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
blog.lumen.com
Open sourcebleepingcomputer.com
Open sourceblog.talosintelligence.com
Open sourceblog.malwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.