North Korea-Linked Konni APT Group – Active IOCs
2024-10-30 • Rewterz •
https://www.rewterz.com/threat-advisory/north-korea-linked-konni-apt-group-active-iocs-37014
This APT group was detected targeting the Russian diplomatic sector in January 2022, employing a spear phishing theme for New Year's Eve festivities as bait. The North Korean hacker group distributes Konni RAT via phishing messages or emails. KONNI has been linked to various alleged North Korean attacks targeting political groups in Russia, East Asia, Europe, and the Middle East. It is believed to be based in North Korea and is known for targeting government agencies and organizations in South Korea and the United States.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | phasechangesolutions.com | 2024-07-12 | 2024-10-30 |
| DOMAIN | cammirando.com | 2024-04-12 | 2024-10-30 |
Related Actors
Related Reports
Shares tag: Konni • Shares 1 IOC • Published within a week
Shares tag: Konni • Shares 2 IOCs
Shares tag: Konni • Shares 1 IOC
Shares tag: Konni • Same author: Rewterz
Shares tag: Konni • Same author: Rewterz
Shares tag: Konni • Published within a month