Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon

Konni (also known as Earth Imp, Opal Sleet, Osmium, TA406, and Vedalia), a threat actor linked to North Korea, has been attributed with a new series of attacks aimed at stealing data from and remotely controlling both Android and Windows devices.

According to a technical report by the Genians Security Center (GSC), attackers posed as psychological counselors and North Korean human rights activists, spreading malware that was disguised as stress-relief programs.

What stands out regarding the attacks aimed at Android devices is the capacity of the malicious actors to take advantage of Google’s Find Hub (previously Find My Device) asset tracking services to carry out remote resets on victim devices, resulting in personal data being deleted without authorization. In early September 2025, the activity was detected.

This development is the first instance in which the hacking group has exploited legitimate management functions to carry out remote resets of mobile devices read more about Konni Hackers Turn Google’s Find Hub into a Remote Data-Wiping Weapon.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *