Threat reportMalwareTL-2026-1529

Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy EndRAT, RftRAT, RemcosRAT

highACTIVE

Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy (TL-2026-1529), also tracked as Operation Poseidon follow-on campaign, is a high-severity malware campaign, first published 2026-03-16. It is attributed to Konni APT (North Korea) with high confidence, affects Microsoft Windows (LNK/PowerShell/Scheduled Tasks), maps to 28 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
1Konni APT
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1529

Threat ID
TL-2026-1529
Also known as
Operation Poseidon follow-on campaign, KakaoTalk-Linked Spear-Phishing Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Konni APT
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
government administration, ngohumanrights, policyresearch, education
Target regions
south korea, East Asia
Detection rules
9
Indicators of compromise
28

Malware and tooling in Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy

Malware and tooling: EndRAT, KONNI, Remcos, RftRAT, AutoIt3.exe, RDP Wrapper

How Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy works

The North Korea-linked Konni APT group ran a spear-phishing campaign disguised as a North Korean human rights lecturer appointment notice, delivering a self-locating malicious LNK file inside a ZIP archive that deploys EndRAT, RftRAT, and RemcosRAT. Attackers then hijacked victims' compromised KakaoTalk PC sessions to redistribute the lure to trusted contacts, achieving worm-like secondary propagation.

Genians Security Center (GSC) identified a multi-stage Konni APT campaign that begins with a spear-phishing email disguised as an official notice appointing the recipient as a 'North Korean human rights lecturer.' The email delivers a ZIP archive containing a malicious LNK (Windows shortcut) file masquerading with a document icon. The LNK uses a self-locating mechanism keyed to a fixed file size constant (0x001DBB82 / 1,948,546 bytes) to find and decode an embedded, XOR-encoded (key 0x3D) payload stored at offset 0x1892 (size 0x1D79FB bytes) within itself. Execution proceeds through 32-bit PowerShell (SysWOW64) launched via cmd.exe, which downloads a second-stage AutoIt3.exe interpreter and an AutoIt-compiled payload (APDNHFU.pdf, actually an A3X script container) from the attacker's WordPress-based C2 at drfeysal[.]com. Persistence is established via a Scheduled Task named 'APDNHFU' that re-triggers every minute for 365 days, and the original LNK deletes itself post-execution as an anti-forensic measure, leaving behind a decoy PDF.

The first payload, EndRAT, is an AutoIt-compiled (A3X) implant using dummy ASCII prefix/suffix padding to defeat signature-based detection. It communicates over TCP port 80 using a custom application-layer protocol (not real HTTP) framed with 'endServer9688'/'endClient9688' delimiters, and supports file management, remote shell, bidirectional file transfer (30 MB cap), and JSON-based beaconing to 185.21.14[.]249 and a secondary Finland-hosted node at 157.180.88[.]26. EndRAT persists by writing new .au3 files padded with random garbage and re-registering itself via a BAT file plus schtasks on a 5-10 minute interval. A build-path artifact recovered from the sample ('D:\3_Attack Weapon\Autoit\Build__Poseidon - Manage\client3.3.14.a3x') directly links this activity to the operator's earlier 'Operation Poseidon' campaign (Genians, January 2026), which weaponized Google/Naver ad click-tracking redirection URLs to deliver EndRAT via compromised WordPress sites.

The second payload, RftRAT (delivered as cliconfg.au3), uses SUB-based repeated-key string decoding for obfuscation and beacons to a Japan-hosted C2 at 96.62.214[.]5 over port 443 in an attempt to blend in with legitimate HTTPS traffic. It supports cmd, exit, download, upload, listdir, delete, and run commands. This Japan-based infrastructure correlates with C2 nodes seen in earlier, previously attributed Konni operations, reinforcing attribution confidence.

The third payload, RemcosRAT (delivered as sqlite4.au3), is a commercial-grade RAT (originally marketed by Breaking Security as a legitimate remote administration tool since 2016) repurposed for espionage. Its configuration is stored RC4-encrypted inside the PE resource section (SETTINGS entry under RCData), with the RC4 key length encoded in the first configuration byte (0x99 observed). Remcos beacons to a Netherlands-hosted C2 at 178.16.54[.]208 and provides keylogging, credential/browser data theft, UAC bypass for privilege elevation, process injection/hollowing for defense evasion, and full remote administration (live shell, file manager, registry editor).

Post-compromise, the attacker deployed additional persistence artifacts across the filesystem, including two Startup-folder LNKs (Start_Web.lnk launching C:\ProgramData\NuGetPacks\AutoIt3.exe against mmlib.au3, and SVC_Init.lnk launching C:\Users\Public\etaxSign\AutoIt3.exe against cliconfg.au3), concealed payload directories under C:\ProgramData\Casio\ (sqlite4.au3, svc.exe, taskhosts.exe), C:\ProgramData\Startup\Spoolsv.exe, C:\ProgramData\remcos\logs.dat, and an installed RDP Wrapper under C:\Program Files\ to enable persistent remote desktop access alongside the RAT channels.

The campaign's distinguishing secondary-propagation stage involved the attacker abusing the victim's already-authenticated KakaoTalk PC client session -- rather than compromising KakaoTalk itself -- to selectively message specific contacts from the victim's friend list with a new lure ('North Korea-related video proposal'), weaponizing the implicit trust of the messenger relationship to drive further infections. This technique mirrors prior Kimsuky/Konni abuse of KakaoTalk documented by industry researchers.

Genians attributes the campaign to Konni APT with high confidence based on: reuse of Japan-hosted C2 infrastructure tied to earlier Konni operations; consistent multi-RAT tradecraft (EndRAT/RftRAT/RemcosRAT combined deployment); the 'Poseidon' build-path artifact tying this activity directly to the January 2026 Operation Poseidon campaign; and continuity of social-engineering lures themed around North Korean human rights and government/NGO impersonation, a signature Konni/Kimsuky targeting pattern. Konni (MITRE ATT&CK software S0356) is a North Korea-nexus RAT tool family active since at least 2014 with code overlap to NOKKI, historically associated with APT37 and operating under the broader DPRK Kimsuky (G0094) umbrella of state-sponsored cyber espionage activity targeting South Korean government, NGO, and human-rights-adjacent targets. No CVE applies -- the intrusion chain relies entirely on social engineering and native Windows LNK/PowerShell/AutoIt execution rather than a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1529

Collection

T1005 Data from Local System; T1115 Clipboard Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.007 JavaScript; T1204.002 Malicious File

Persistence

T1053.005 Scheduled Task; T1133 External Remote Services; T1547.001 Registry Run Keys / Startup Folder; T1547.005 Security Support Provider

Credential Access

T1056.001 Keylogging; T1555.003 Credentials from Web Browsers

Command and Control

T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography

Discovery

T1082 System Information Discovery; T1087 Account Discovery

Impact

T1499 Endpoint Denial of Service

Privilege Escalation

T1548.002 Bypass User Account Control

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.008 Malvertising; T1584.004 Server

Affected products and versions in Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy

  • Microsoft — Windows (LNK/PowerShell/Scheduled Tasks)
    Vulnerable versions: All supported Windows versions (social engineering, not a version-specific vulnerability)
  • Kakao Corp — KakaoTalk PC client
    Vulnerable versions: Any version where PC session is already authenticated and locally compromised

Remediation for Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy

Immediate actions

  • Block C2 IPs 185.21.14.249, 157.180.88.26, 96.62.214.5, 178.16.54.208 and domain drfeysal.com at perimeter/DNS/proxy
  • Hunt for scheduled task named APDNHFU and any 1-minute-interval schtasks created post-archive-extraction
  • Hunt for AutoIt3.exe execution with .au3 script arguments outside known-good software inventory
  • Search for Startup-folder LNKs Start_Web.lnk and SVC_Init.lnk and ProgramData paths (Casio, NuGetPacks, remcos, Startup\Spoolsv.exe)
  • Force logout and re-authenticate all active KakaoTalk PC sessions on potentially affected endpoints; warn users about unsolicited North Korea/human-rights themed lures shared via messenger
  • Search mail gateway logs for ZIP attachments containing LNK files with document icons themed around lecturer appointment notices

Workarounds

  • Disable Windows Script Host and restrict LNK execution from removable/archived sources via Group Policy where feasible
  • Enable PowerShell Constrained Language Mode and Script Block Logging to increase visibility into the SysWOW64 PowerShell stage

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to LNK-spawns-PowerShell-spawns-AutoIt chains rather than static hash/IOC matching
  • Restrict or monitor AutoIt3.exe execution via application allowlisting given its recurring abuse as a loader by this actor
  • Implement DMARC/DKIM/SPF enforcement and attachment sandboxing for inbound email, especially ZIP/LNK combinations
  • Deploy network detection for the custom endServer9688/endClient9688 socket protocol and non-standard TLS handshakes on port 443
  • Establish organizational policy restricting execution of messenger-shared files without verification, given the KakaoTalk secondary-propagation vector

Timeline of Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy

  • Prior reporting documents Kimsuky/Konni-linked actors abusing KakaoTalk and targeting South Korean Android devices with remote wipe tactics, establishing precedent for messenger-abuse tradecraft.
  • Genians publishes Operation Poseidon report detailing Konni APT abuse of Google/Naver ad click-tracking redirection to deliver EndRAT via compromised WordPress sites, establishing the build-lineage later found in this campaign.
  • Estimated window of active spear-phishing delivery of the 'North Korean human rights lecturer' appointment lure prior to Genians' public report.
  • SysWOW64 PowerShell launched via cmd.exe downloads AutoIt3.exe interpreter and APDNHFU.pdf (EndRAT A3X payload) from drfeysal[.]com C2.
  • Victims receive spear-phishing email with ZIP attachment containing malicious LNK disguised as a document; execution triggers self-locating XOR-decoded payload extraction.
  • EndRAT establishes custom-protocol beaconing over port 80 to 185.21.14[.]249 (and 157.180.88[.]26), enabling remote shell and file transfer.
  • Scheduled Task 'APDNHFU' created with 1-minute recurrence over 365 days; original LNK self-deletes to remove forensic trace.
  • RemcosRAT (sqlite4.au3) deployed with RC4-encrypted configuration, beaconing to Netherlands-hosted C2 178.16.54[.]208; keylogging and credential theft begin.
  • RftRAT (cliconfg.au3) deployed with SUB-obfuscated strings, beaconing to Japan-hosted C2 96.62.214[.]5 over port 443.
  • Attacker abuses victim's authenticated KakaoTalk PC session to message selected contacts with a new 'North Korea-related video proposal' lure, propagating the campaign through trusted relationships.
  • Genians Security Center publishes technical report attributing the campaign to Konni APT and disclosing IOCs, TTPs, and the KakaoTalk abuse vector.

Sources cited for Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy

Detection coverage for TL-2026-1529

As of 2026-03-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1529 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats