Find notable cyber news and cases, enriched with sources, timelines, and signals.

KONNI AutoIt loader and RAT delivery activity

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

KONNI operators used a disguised MSI installer to drop an AutoIt loader that established persistence and fetched additional payloads, raising the impact of the intrusion chain. The loader connected to C2 servers and enabled delivery of RemcosRAT, QuasarRAT, and RftRAT, expanding remote control over compromised systems. The activity mattered because the malware chain paired social engineering with staged payload delivery to support follow-on compromise and destructive abuse. The operation also used trusted messaging channels, increasing the chance that victims would execute the installer.

Related Happenings

SharkLoader loader activity deploying Cobalt Strike Beacon

Malware Activity
H score30 First: 26.06.2026 21:17 Last: 26.06.2026 21:17 Sources 1

About this happening: A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...

GlassWorm v2 cloned VS Code extension loaders

Malware Activity
H score30 First: 27.04.2026 14:23 Last: 27.04.2026 14:23 Sources 1

About this happening: The GlassWorm v2 malware activity now uses cloned VS Code extensions on Open VSX to deliver payloads that steal credentials, deploy a RAT, and spread across multip...

Konni multi-stage KakaoTalk phishing campaign

Campaign
H score31 First: 17.03.2026 11:53 Last: 17.03.2026 11:53 Sources 1

About this happening: The Konni operation is expanding through spear-phishing and abused KakaoTalk desktop accounts, increasing the chance that one compromise reaches multiple contacts. It...

KONNI KakaoTalk and Google Find Hub Android-wiping campaign

Campaign
H score35 First: 11.11.2025 02:46 Last: 11.11.2025 02:46 Sources 1

How related: The operation, uncovered by the Genians Security Center (GSC), is linked to the long-running KONNI advanced persistent threat (APT) campaign, associated with North Korea’s Kimsuky and APT37 groups.

About this happening: The KONNI operation is actively combining KakaoTalk spear-phishing with Google Find Hub abuse to track targets and remotely wipe Android devices, raising data-loss...

InedibleOchotense spear phishing campaign impersonating ESET

Campaign
H score33 First: 07.11.2025 14:20 Last: 07.11.2025 14:20 Sources 1

About this happening: The InedibleOchotense spear phishing campaign impersonating ESET delivered a trojanized installer and Kalambur backdoor, creating a direct infection risk for targe...

Timeline

  1. 11.11.2025 18:45 2 articles · 8mo ago

    GSC reports KONNI abuse of Google Find Hub

    Initial Disclosure

    Genians Security Center described a KONNI APT campaign linked to Kimsuky and APT37 that used compromised KakaoTalk accounts to spread disguised MSI files, steal Google account credentials, and abuse Google’s Find Hub to remotely wipe Android phones and tablets, marking the first confirmed state-sponsored abuse of the feature for destructive operations.

    Show sources