Konni
2017-05-03 • Cisco Talos • KONNI: A Malware Under The Radar For Years
Konni is the name Cisco Talos gave in 2017 to a remote-access malware family it found delivering information-stealing and remote-control capability through spear-phishing emails with decoy documents, in campaigns dating back to 2014 that increasingly targeted individuals and organizations connected to North Korea-related diplomatic and humanitarian affairs. The malware and associated intrusion activity were subsequently tracked by other vendors as a distinct campaign and, later, an actor: Palo Alto Networks referred to malware families "typically associated with the Konni Group" in a 2019-2020 spear-phishing campaign against a U.S. government agency, and Cluster25 described a 2022 operation as conducted by the "North Korean APT group Konni" targeting Russia's diplomatic sector. Malwarebytes, by contrast, assessed in 2022 that the North Korean threat actor using Konni malware operates under what it called the Kimsuky umbrella, illustrating ongoing disagreement among researchers over whether Konni represents an independent group or a toolset shared within a broader North Korean cluster.
-
12
Related Actors
-
211
Related Reports