Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures
2026-09-22 • SOCRadar •
https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/
SOCRadar attributes Operation Conflict Compass to Konni with moderate confidence, linking the campaign to Ukraine-focused espionage through malicious LNK files and trojanized Zoom installers. The infection chain deploys VelvetCake, a lightweight PowerShell task runner that retrieves server-side modules, establishes scheduled-task persistence, and executes reconnaissance and collection commands. Recovered modules enumerate hosts and security software, capture screens, and exfiltrate staged data through attacker-controlled infrastructure. The assessment draws on targeting, shared infrastructure, URL patterns, payload characteristics, and operator activity aligned with UTC+9 working hours.