SOCRadar reported that the DPRK-aligned Konni threat actor, also tracked as TA406, is conducting Operation Conflict Compass against Ukraine-focused organizations. The campaign uses spear-phishing ZIP archives containing malicious Windows shortcut (.LNK) files disguised as PDFs and may also use trojanized Zoom installers to deploy VelvetCake, a custom PowerShell task runner. VelvetCake creates scheduled-task persistence, retrieves PowerShell modules from attacker infrastructure on demand, performs host reconnaissance and screen capture, and exfiltrates collected data.
The operation is assessed, with moderate confidence, to support intelligence collection related to the Russia-Ukraine war and likely targets foreign-policy, diplomatic, defense, and research entities. It follows TA406 activity observed against Ukrainian government organizations in 2025, where lures impersonated think tanks and exploited political themes to deliver credential-harvesting pages or archive-based malware chains; one chain similarly used a benign PDF alongside an LNK that launched encoded PowerShell and created a scheduled task named Windows Themes Update. Organizations should treat unsolicited archives, PDF-like shortcuts, and unexpected Zoom installers as high-risk, and investigate scheduled-task creation and PowerShell execution originating from user download locations.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
Public researchers identified samples related to the VelvetCake components in early September 2026.
Command-and-control domains associated with the later Operation Conflict Compass campaign appeared as early as August 3, 2026.
In February 2025, DPRK-linked TA406 targeted Ukrainian government entities with credential-harvesting and malware-delivery phishing campaigns. The activity used spoofed think-tank personas and Ukraine political lures to collect strategic intelligence on the war.
SOCRadar designated Operation Conflict Compass as a Ukraine-focused cyberespionage campaign assessed with moderate confidence to be operated by DPRK-aligned Konni/TA406. The operation used spear-phishing ZIP attachments containing PDF-disguised LNK files and suspected trojanized Zoom installers to deploy the VelvetCake PowerShell task runner.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcesocradar.io
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.