Konni is a Windows remote access trojan first observed in 2014 and used in North Korean cyberespionage operations, including campaigns linked to APT37. It has targeted political and government-related organizations across Russia, East Asia, Europe, and the Middle East.
Konni supports remote command execution, downloading and executing additional payloads, browser credential theft, screenshot capture, file deletion, and data exfiltration. It can steal credential-bearing profiles from Firefox, Chrome, and Opera, and collect usernames, IP addresses, running-process information, system details, and directory listings. Variants maintain persistence through registry autostart entries, service-related registry modifications, or shortcuts placed in Windows startup locations. Stolen information and command-and-control data can be concealed using custom Base64 encoding and dynamically encoded request parameters.
Delivery methods include phishing with malicious documents or Windows shortcut lures, as well as backdoored software installers. Shortcut-based infection chains disguise executable shortcuts as documents and display benign decoys while launching layered PowerShell, VBScript, and batch-script components. These chains can extract XOR-encoded embedded components and use native Windows utilities to decode, unpack, download, and execute payloads. Defense-evasion techniques include whitespace padding that hides shortcut command arguments, deceptive naming, script obfuscation, suppressed command output, and deletion of intermediate artifacts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During our analysis, we discovered that some North Korean threat actors, such as Earth Manticore (APT37) and Earth Imp (Konni), tended to use extremely large .lnk files with large amounts of whitespace and other junk content to further evade detection.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During our analysis, we discovered that some North Korean threat actors, such as Earth Manticore (APT37) and Earth Imp (Konni), tended to use extremely large .lnk files with large amounts of whitespace and other junk content to further evade detection.
During our analysis, we discovered that some North Korean threat actors, such as Earth Manticore (APT37) and Earth Imp (Konni), tended to use extremely large .lnk files with large amounts of whitespace and other junk content to further evade detection.
In this campaign, the hackers use malware known as Konni, a remote access trojan (RAT) capable of establishing persistence and performing privilege escalation on the host.
The phishing campaign started since at least October 19, 2021, deploying Konni malware, a remote administration tool (RAT) associated with the cyber activity from North Korean hackers known as APT37.
The phishing campaign started since at least October 19, 2021, deploying Konni malware, a remote administration tool (RAT) associated with the cyber activity from North Korean hackers known as APT37.
40 distinct techniques documented for this family, organized by ATT&CK tactic.
204 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
143 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Konni is identified as the malware involved in a campaign targeting Ukraine using malicious LNK-file lures.
Konni is mentioned in connection with North Korean threat actor activity using oversized malicious .lnk files to evade detection while exploiting the shortcut vulnerability.
A long-running RAT/backdoor family repeatedly linked in the content to North Korean activity, including diplomatic targeting and phishing-based delivery.
A PowerShell backdoor associated with Konni activity, described here as AI-assisted in its code generation while retaining established delivery and execution tradecraft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.