Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

Foto: The Hacker News
North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim's KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat intelligence firm Genians to a hacking group referred to as Konni. "Initial access was achieved through a spear-phishing email disguised as a
North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim's KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat intelligence firm Genians to a hacking group referred to as Konni. "Initial access was achieved through a spear-phishing email disguised as a
More from Security

Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware

Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026

INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime

Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
Related Articles

GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
21h
Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse
Mar 16
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration
Mar 14