Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware
Phishing has been used by North Korean threat actors to breach targets, gain access to a victim's KakaoTalk desktop application, and spread malicious payloads to specific contacts.
Genians, a South Korean threat intelligence firm, has linked the behavior to a hacker collective known as Konni. According to a study by the Genians Security Center (GSC), the initial access was obtained through a spear-phishing email that posed as a notification designating the recipient as a North Korean human rights speaker.
The victim was infected with remote access malware after the spear-phishing attempt was successful and they ran a malicious LNK file. For a considerable amount of time, the malware remained hidden and persistent on the victim's endpoint, stealing confidential data and internal docu...

