Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

Phishing has been used by North Korean threat actors to breach targets, gain access to a victim’s KakaoTalk desktop application, and spread malicious payloads to specific contacts.

Genians, a South Korean threat intelligence firm, has linked the behavior to a hacker collective known as Konni. According to a study by the Genians Security Center (GSC), the initial access was obtained through a spear-phishing email that posed as a notification designating the recipient as a North Korean human rights speaker.

The victim was infected with remote access malware after the spear-phishing attempt was successful and they ran a malicious LNK file. For a considerable amount of time, the malware remained hidden and persistent on the victim’s endpoint, stealing confidential data and internal documents.

According to reports, the threat actor stayed on the compromised host for a long time, using the illegal access to steal corporate information and utilize the KakaoTalk app read more about Konni Deploys EndRAT Through Phishing Uses KakaoTalk to Propagate Malware.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *