CISA warned that attackers were distributing KONNI malware through phishing emails carrying Microsoft Word documents with malicious VBA macros. The documents altered their appearance to pressure recipients into enabling content, after which the macros checked system architecture and used the Windows command shell and CertUtil to download, decode, and execute additional payloads. CISA described KONNI as a remote administration tool capable of file theft, keylogging, screenshot capture, arbitrary command execution, persistence, privilege escalation, and data exfiltration.
The activity aligns with multiple MITRE ATT&CK techniques across the intrusion lifecycle, including phishing-based initial access, macro execution, discovery, command-and-control, and exfiltration. Among the mapped behaviors are host and network reconnaissance actions such as collecting local configuration details with native utilities, consistent with ATT&CK technique T1016 for system network configuration discovery. CISA said the alert included ATT&CK mappings, Snort signatures, and mitigation guidance to help defenders detect and block the campaign.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
CISA published alert AA20-227A describing cyber actors using phishing emails with malicious Microsoft Word VBA macros to deploy KONNI malware, along with technical details, ATT&CK mappings, Snort signatures, and mitigations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
us-cert.cisa.gov
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.