Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy EndRAT, RftRAT, RemcosRAT — Threadlinqs Intelligence
As of 2026-03-16, Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy EndRAT, RftRAT, RemcosRAT is a high-severity malware threat attributed to Konni APT (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1529 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Konni APT · North Korea (DPRK) · ESPIONAGE
The North Korea-linked Konni APT group ran a spear-phishing campaign disguised as a North Korean human rights lecturer appointment notice, delivering a self-locating malicious LNK file inside a ZIP
Genians Security Center (GSC) identified a multi-stage Konni APT campaign that begins with a spear-phishing email disguised as an official notice appointing the recipient as a 'North Korean human rights lecturer.' The email delivers a ZIP archive containing a malicious LNK (Windows shortcut) file masquerading with a document icon. The LNK uses a self-locating mechanism keyed to a fixed file size constant (0x001DBB82 / 1,948,546 bytes) to find and decode an embedded, XOR-encoded (key 0x3D) payload stored at offset 0x1892 (size 0x1D79FB bytes) within itself. Execution proceeds through 32-bit PowerShell (SysWOW64) launched via cmd.exe, which downloads a second-stage AutoIt3.exe interpreter and an AutoIt-compiled payload (APDNHFU.pdf, actually an A3X script container) from the attacker's WordPress-based C2 at drfeysal[.]com. Persistence is established via a Scheduled Task named 'APDNHFU' that re-triggers every minute for 365 days, and the original LNK deletes itself post-execution as an anti-forensic measure, leaving behind a decoy PDF.
The first payload, EndRAT, is an AutoIt-compiled (A3X) implant using dummy ASCII prefix/suffix padding to defeat signature-based detection. It communicates over TCP port 80 using a custom application-layer protocol (not real HTTP) framed with 'endServer9688'/'endClient9688' delimiters, and supports file management, remote shell, bidirectional file transfer (30 MB cap), and JSON-based beaconing to 185.21.14[.]249 and a secondary Finland-hosted node at 157.180.88[.]26. EndRAT persists by writing new .au3 files padded with random garbage and re-registering itself via a BAT file plus schtasks on a 5-10 minute interval. A build-path artifact recovered from the sample ('D:\3_Attack Weapon\Autoit\Build__Poseidon - Manage\client3.3.14.a3x') directly links this activity to the operator's earlier 'Operation Poseidon' campaign (Genians, January 2026), which weaponized Google/Naver ad click-tracking redirection URLs to deliver EndRAT via compromised WordPress sites.
The second payload, RftRAT (delivered as cliconfg.au3), uses SUB-based repeated-key string decoding for obfuscation and beacons to a Japan-hosted C2 at 96.62.214[.]5 over port 443 in an attempt to blend in with legitimate HTTPS traffic. It supports cmd, exit, download, upload, listdir, delete, and run commands. This Japan-based infrastructure correlates with C2 nodes seen in earlier, previously attributed Konni operations, reinforcing attribution confidence.
The third payload, RemcosRAT (delivered as sqlite4.au3), is a commercial-grade RAT (originally marketed by Breaking Security as a legitimate remote administration tool since 2016) repurposed for espionage. Its configuration is stored RC4-encrypted inside the PE resource section (SETTINGS entry under RCData), with the RC4 key length encoded in the first configuration byte (0x99 observed). Remcos beacons to a Netherlands-hosted C2 at 178.16.54[.]208 and provides keylogging, credential/browser data theft, UAC bypass for privilege elevation, process injection/hollowing for defense evasion, and full remote administration (live shell, file manager, registry editor).
Post-compromise, the attacker deployed additional persistence artifacts across the filesystem, including two Startup-folder LNKs (Start_Web.lnk launching C:\ProgramData\NuGetPacks\AutoIt3.exe against mmlib.au3, and SVC_Init.lnk launching C:\Users\Public\etaxSign\AutoIt3.exe against cliconfg.au3), concealed payload directories under C:\ProgramData\Casio\ (sqlite4.au3, svc.exe, taskhosts.exe), C:\ProgramData\Startup\Spoolsv.exe, C:\ProgramData\remcos\logs.dat, and an installed RDP Wrapper under C:\Program Files\ to enable persistent remote desktop access alongside the RAT channels.
The campaign's distinguishing secondary-propagation stage involved the attacker abusing the victim's already-authenticated KakaoTalk PC client session -- rather than compromising KakaoTalk itself -- to selectively message specific contacts from the victim's
Target sectors: government administration, ngohumanrights, policyresearch, education
Target regions: south korea, East Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1059.001, T1059.007, T1053.005, T1204.002, T1547.001, T1547.005, T1053.005, T1133, T1548.002