Konni APT KakaoTalk spear-phishing campaign targeting Android users in South Korea
Campaign
Summary
Hide ▲
Show ▼
A Konni APT operation is using spear-phishing and KakaoTalk to compromise Android users in South Korea, enabling device compromise and malware spread. The multi-stage tradecraft matters because it combines trusted messaging accounts, social engineering, and follow-on propagation to widen impact across a Korean user cohort. The activity began in July of last year and was still being used through Sept. 15.
Related Happenings
Kimsuky March-April 2026 campaign against South Korean military and corporate entities
Campaign
H score38
First: 29.05.2026 08:57
Last: 29.05.2026 08:57
Sources 1
About this happening:
The Kimsuky campaign ran through March and April 2026, using spoofed security-installation pages and a fake Webex lure against South Korean military and corporat...
Kimsuky March-April 2026 campaign against South Korean military and corporate entities
CampaignAbout this happening: The Kimsuky campaign ran through March and April 2026, using spoofed security-installation pages and a fake Webex lure against South Korean military and corporat...
TrickMo C TikTok-lure campaign targeting banking and wallet users in France, Italy, and Austria
Campaign
H score33
First: 11.05.2026 18:15
Last: 11.05.2026 18:15
Sources 1
About this happening:
The TrickMo operators ran an active TikTok-themed campaign between January and February 2026, targeting banking and wallet users in France, Italy and Austria....
TrickMo C TikTok-lure campaign targeting banking and wallet users in France, Italy, and Austria
CampaignAbout this happening: The TrickMo operators ran an active TikTok-themed campaign between January and February 2026, targeting banking and wallet users in France, Italy and Austria....
APT37 BirdCall Android supply-chain campaign
Campaign
H score36
First: 05.05.2026 12:04
Last: 05.05.2026 12:04
Sources 1
About this happening:
The APT37 campaign now delivers a new Android variant of BirdCall through trojanized APKs on sqgame[.]net, expanding the operation beyond its known Windows...
APT37 BirdCall Android supply-chain campaign
CampaignAbout this happening: The APT37 campaign now delivers a new Android variant of BirdCall through trojanized APKs on sqgame[.]net, expanding the operation beyond its known Windows...
Mirax Android banking trojan with residential proxy nodes
Malware Activity
H score37
First: 13.04.2026 17:30
Last: 13.04.2026 17:30
Sources 1
About this happening:
Mirax is spreading across Europe with remote access and residential proxy features, increasing the risk of device compromise, data theft, and traffic abuse. The Androi...
Mirax Android banking trojan with residential proxy nodes
Malware ActivityAbout this happening: Mirax is spreading across Europe with remote access and residential proxy features, increasing the risk of device compromise, data theft, and traffic abuse. The Androi...
Android RAT campaign using Hugging Face dropper lure
Campaign
H score37
First: 16.02.2026 12:24
Last: 16.02.2026 12:24
Sources 1
About this happening:
In recent weeks, a live Android RAT campaign has used Hugging Face to deliver malicious APKs through a fake-update lure. The operation starts with a dropper app, such as *...
Android RAT campaign using Hugging Face dropper lure
CampaignAbout this happening: In recent weeks, a live Android RAT campaign has used Hugging Face to deliver malicious APKs through a fake-update lure. The operation starts with a dropper app, such as *...
Timeline
-
11.11.2025 13:40 1 articles · 8mo ago
Psychological counselor KakaoTalk account compromise and remote reset
Exploitation ObservedAttackers compromised the KakaoTalk account of a psychological counselor supporting young North Korean defectors on Sept. 5, used Find Hub's location query, and executed a remote reset command on both an Android smartphone and a tablet, disrupting notification and message alerts and delaying detection and response.
Show sources
- Kimsuky APT Takes Over South Korean Androids, Abuses KakaoTalk — www.darkreading.com — 11.11.2025 13:40
-
11.11.2025 13:40 1 articles · 8mo ago
Separate KakaoTalk account used for en masse malware distribution
Campaign Scope UpdateTen days later on Sept. 15, attackers used a separate victim's KakaoTalk account to distribute malicious AutoIt scripts and modules, including LilithRAT and RemcosRAT, in a simultaneous wave that broadened the campaign's malware delivery through trusted contacts.
Show sources
- Kimsuky APT Takes Over South Korean Androids, Abuses KakaoTalk — www.darkreading.com — 11.11.2025 13:40
-
11.11.2025 13:40 2 articles · 8mo ago
Genians attributes Konni's Android remote reset campaign
Initial DisclosureGenians disclosed a Konni campaign, also tracked as APT37, TA406, and Thallium under the Kimsuky umbrella, that targeted Android users in South Korea with social engineering, Google Find Hub abuse, and KakaoTalk-based malware delivery; the researchers said the operation remotely reset devices, deleted personal data, and released IoCs linked to the campaign.
Show sources
- Kimsuky APT Takes Over South Korean Androids, Abuses KakaoTalk — www.darkreading.com — 11.11.2025 13:40
- Kimsuky APT Takes Over South Korean Androids, Abuses KakaoTalk — www.darkreading.com — 11.11.2025 13:40