Konni is a North Korean state-linked threat actor also tracked as Earth Imp, Opal Sleet, Osmium, TA406, and PlaneDown. Historically focused on cyberespionage, it targets South Korean government officials, diplomats, policy researchers, and people connected to North Korean human-rights and defector communities. Its targeting also includes Russian diplomatic interests, Ukraine-focused individuals and organizations, and cryptocurrency and blockchain professionals. Confirmed cryptocurrency-related victims include organizations in the United States and United Kingdom. Konni has operational associations with the broader Kimsuky ecosystem, but the names should not be treated as universally interchangeable; use of the Konni malware family by other actors likewise does not establish actor equivalence. Konni commonly obtains access through spear-phishing, impersonation of South Korean government agencies, and malicious Windows shortcuts disguised as documents inside archives. Infection chains use PowerShell, VBScript, batch scripts, and AutoIt, frequently displaying legitimate decoys while installing malware. The group has exploited WinRAR vulnerability CVE-2023-38831 and abused Windows shortcut interface misrepresentation to conceal malicious commands. Persistence mechanisms include scheduled tasks, startup entries, and registry autorun mechanisms. Its operations collect documents, account information, host inventories, and other sensitive data, using remote-access tools including EndRAT, RftRAT, RemcosRAT, and QuasarRAT. Konni also abuses compromised KakaoTalk desktop sessions to distribute malware to trusted contacts. After compromising Google accounts, operators have used Google's Find Hub to locate and remotely reset Android devices, disrupting victims and delaying detection. They have deleted security notifications to conceal account compromise. By late 2025, Konni had expanded into macOS attacks against cryptocurrency professionals. These campaigns use document-disguised AppleScript applications and fraudulent system prompts to capture passwords, manipulate privacy permissions, and establish LaunchAgent persistence. Deployed implants include FileRATClient and an EggShell variant, supporting reconnaissance, keylogging, screen and audiovisual capture, file access, and remote command execution. Its activity consequently spans traditional intelligence collection and cryptocurrency-focused operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
DPRK aligned TA406 (Opal Sleet) chained CVE-2026-21510 with CVE-2026-21509 in active campaigns.
CVE-2023-38831, the WinRAR zero-day remote code execution vulnerability, has been exploited in the wild to distribute several malware families.
CVE-2026-21509 (Microsoft Office RTF/OLE Code Execution) was weaponized by Russia linked TA422 (APT28) within a single day of public disclosure.
ZDI identified nearly 1,000 malicious .lnk files abusing ZDI-CAN-25373 (aka ZDI-25-148), a vulnerability that allows attackers to execute hidden malicious commands on a victim’s machine by leveraging crafted shortcut files.
34 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted attacks against blockchain technology developers and engineers using AI-generated PowerShell malware.
Conducting a malware campaign, reportedly called Operation Compass, targeting Ukraine-focused individuals and organizations using a résumé/CV-themed social-engineering lure.
Moderate-confidence attribution for an espionage campaign targeting Ukraine-focused individuals and organizations to collect political and military intelligence related to the war.
Targeting Ukraine using phishing lures containing malicious LNK files as part of Operation Conflict Compass.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.