Researchers across multiple reports documented continued KONNI activity using spear-phishing lures tied to geopolitics, cryptocurrency, and regional news, with malware delivered through malicious Word documents, VBA macros, staged DLL payloads, and fake software components. Campaigns used North Korea-themed decoys such as CNN and Yonhap articles, later shifted to Russian-language and Huobi-themed documents, and commonly installed both 32-bit and 64-bit payloads, persisted through rundll32.exe, Windows Run registry keys, scheduled tasks, and downloader chains that fetched additional malware from attacker-controlled HTTP, FTP, and staged web infrastructure disguised as legitimate sites.
Technical analysis showed the malware family evolving from earlier XOR-protected communications to ZIP-compressed, RC4-encrypted, Base64-encoded exfiltration, while retaining capabilities including reconnaissance, file theft, screenshot capture, keylogging, clipboard theft, and payload execution. Later reporting linked the KONNI ecosystem to broader North Korea-aligned operations, citing overlaps with Kimsuky/Thallium in infrastructure, malware formats, credentials, and delivery tradecraft, and describing newer campaigns in South Korea that used compromised KakaoTalk accounts, multiple RAT families, and stolen Google credentials to abuse Android Find Hub for device tracking and remote wiping of victims’ phones.

TTPs, infrastructure, and targeting history in one profile.
19 events from the most recent confirmed update back to the earliest known activity.
Genians said another compromised KakaoTalk account was used on September 15, 2025, to distribute malicious files in a simultaneous wave. The campaign relied on trusted contacts' messenger sessions to spread malware.
Genians reported that on September 5, 2025, a compromised KakaoTalk account belonging to a South Korea-based counselor was used to send a malicious file to a North Korean defector student. The malware was disguised as a "stress-relief program."
Cyber and Ramen noted that Black Lotus Labs linked the infrastructure online-manual.c1[.]biz to a possible Konni campaign in late November 2021. This provided external context for assessing the downloader sample as likely Konni-related.
Cyber and Ramen reported that the DLL malware sample "downloader.dll" was first identified around October 2021. The sample masqueraded as a Foxit Reader extension and contacted online-manual.c1[.]biz to download and unpack a follow-on payload.
ESRC discovered the malicious Russian-language Word document during security monitoring on August 16, 2019. The sample used VBA macros and an ObjectPool stream to abuse certutil.exe, fetch staged payloads from handicap.eu5[.]org, unpack a CAB archive, and connect to FTP infrastructure.
The malicious Word document "О ситуации на Корейском полуострове и перспективах диалога между США и КНДР.doc" had a recorded final modified time of 2019-07-12 09:30:39 UTC. ESRC later assessed the file as part of the Konni malware series.
In June 2019, ESRC published analysis asserting that Konni likely had a strong operational relationship with Kimsuky/Thallium. The report cited overlapping malware traits, archive passwords, export names, decryption routines, infrastructure, and FTP credential patterns.
ESRC identified a May 2019 Konni campaign using a malicious Word document themed as "Huobi Research Weekly (Vol.62) 2019.05.13-2019.05.19.doc." The macro downloaded 1.dat and a decoy DOCX from naoei3-tosma.96[.]lt, then executed the payload and established persistence as ChromSrch.dat.
ESRC linked a later Konni sample to an earlier document named geopol18.doc with a modified time of 2019-01-21 23:36:00 UTC. The earlier sample used Russian-language lure content, Korean codepage 949, a similar macro pattern, and clean.1apps[.]com for staged delivery.
ESRC described a July 2018 phishing campaign impersonating a Korean cryptocurrency exchange that delivered a ZIP archive containing "공지사항.png.vbs." The script used ago2.co[.]kr as C2 and downloaded a benign image plus a Base64-encoded malicious DLL.
ESRC reported that a 2018 Konni phishing document named "_확인 자료.doc" used the C2 domain filer1.1apps[.]com. The report linked this infrastructure to other Konni BlueSky samples.
Fortinet said the malicious Word document reused text from CNN's article "12 things Trump should know about North Korea," which was published on August 9, 2017. That article served as the lure content for the campaign.
Fortinet reported that the installer used in a later KONNI variant carried a PE compilation timestamp of August 8, 2017, if unaltered. The sample dropped 32-bit and 64-bit KONNI DLLs and executed them via rundll32 persistence.
Fortinet reported that the embedded 32-bit and 64-bit KONNI DLLs in the August 2017 installer carried compilation timestamps of July 11, 2017, if unaltered. The DLLs retained file theft, reconnaissance, screenshot, keylogging, and clipboard theft capabilities.
Talos identified a new KONNI distribution campaign on 4 July 2017. The malware used a Yonhap News decoy, dropped 32-bit and 64-bit payloads, established Run-key persistence, and communicated with the new C2 domain member-daumchk[.]netai[.]net.
Talos said the July 2017 KONNI campaign appeared directly related to North Korea's missile launch on 3 July and the ensuing discussion of missile capabilities. The lure document copied a Yonhap article published the same day.
Fortinet stated that the KONNI remote access Trojan was first publicly reported in May 2017. This marks the earliest explicit public disclosure date in the provided references.
ESRC reported that Konni had conducted spear-phishing campaigns since around 2014, initially using North Korea-themed lure documents. Fortinet separately noted the malware family was believed to have been active for more than three years by 2017.
Genians published analysis of a KONNI-linked campaign in which attackers stole Google credentials, queried victims' locations through Find Hub, and remotely wiped Android devices. The report described this as the first confirmed case it had observed of a state-sponsored actor abusing Find Hub for remote wipe and location tracking in an APT campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 107 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
6 references tracked. Mallory keeps watching after this page renders.
genians.co.kr
Open sourcecyberandramen.net
Open sourceblog.alyac.co.kr
Open sourceblog.alyac.co.kr
Open sourceblog.fortinet.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.