New variant of Konni malware used in campaign targetting Russia
2021-08-20 • Malwarebytes •
This blog post was authored by Hossein Jazi In late July 2021, we identified an ongoing spear phishing campaign pushing Konni Rat to target Russia. Konni was first observed in the wild in 2014 and has been potentially linked to the North Korean APT group named APT37. Konni is a Rat that potentially is used by APT37 to target its victims. In those campaigns the actor used lures in Russian language to target Russia.
Indicators of Compromise
Related Actors
Related Reports
Shares tag: Konni • Shares 1 IOC • Same author: Malwarebytes
2022-01-05 •
65% Match
#Konni
Shares tag: Konni
2022-01-03 •
65% Match
North Korean Group “KONNI” Targets The Russian Diplomatic Sector With New Versions Of Malware Implants
Cluster25
Shares tag: Konni
2021-05-21 •
65% Match
#Konni
#T1082
#T1059.003
#T1140
#T1041
#T1071.001
#T1059.007
#T1204.002
#T1566.001
#T1573.001
#T1132.002
#T1055.001
#T1033
#T1569.002
#T1543.003
#T1202
#T1027.001
Shares tag: Konni
Shares tag: Konni
Shares tag: Konni • Shares 1 IOC