Threat reportMalwareTL-2026-1529
Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy EndRAT, RftRAT, RemcosRAT
Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy (TL-2026-1529), also tracked as Operation Poseidon follow-on campaign, is a high-severity malware campaign, first published 2026-03-16. It is attributed to Konni APT (North Korea) with high confidence, affects Microsoft Windows (LNK/PowerShell/Scheduled Tasks), maps to 28 MITRE ATT&CK techniques (T1005, T1027, T1036.005), and is covered by 9 detection rules and 28 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 28MITRE ATT&CK
- Actors
- 1Konni APT
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 28Indicators of compromise
Key facts for TL-2026-1529
- Threat ID
- TL-2026-1529
- Also known as
- Operation Poseidon follow-on campaign, KakaoTalk-Linked Spear-Phishing Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Konni APT
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- government administration, ngohumanrights, policyresearch, education
- Target regions
- south korea, East Asia
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy
Malware and tooling: EndRAT, KONNI, Remcos, RftRAT, AutoIt3.exe, RDP Wrapper
How Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy works
The North Korea-linked Konni APT group ran a spear-phishing campaign disguised as a North Korean human rights lecturer appointment notice, delivering a self-locating malicious LNK file inside a ZIP archive that deploys EndRAT, RftRAT, and RemcosRAT. Attackers then hijacked victims' compromised KakaoTalk PC sessions to redistribute the lure to trusted contacts, achieving worm-like secondary propagation.
Genians Security Center (GSC) identified a multi-stage Konni APT campaign that begins with a spear-phishing email disguised as an official notice appointing the recipient as a 'North Korean human rights lecturer.' The email delivers a ZIP archive containing a malicious LNK (Windows shortcut) file masquerading with a document icon. The LNK uses a self-locating mechanism keyed to a fixed file size constant (0x001DBB82 / 1,948,546 bytes) to find and decode an embedded, XOR-encoded (key 0x3D) payload stored at offset 0x1892 (size 0x1D79FB bytes) within itself. Execution proceeds through 32-bit PowerShell (SysWOW64) launched via cmd.exe, which downloads a second-stage AutoIt3.exe interpreter and an AutoIt-compiled payload (APDNHFU.pdf, actually an A3X script container) from the attacker's WordPress-based C2 at drfeysal[.]com. Persistence is established via a Scheduled Task named 'APDNHFU' that re-triggers every minute for 365 days, and the original LNK deletes itself post-execution as an anti-forensic measure, leaving behind a decoy PDF.
The first payload, EndRAT, is an AutoIt-compiled (A3X) implant using dummy ASCII prefix/suffix padding to defeat signature-based detection. It communicates over TCP port 80 using a custom application-layer protocol (not real HTTP) framed with 'endServer9688'/'endClient9688' delimiters, and supports file management, remote shell, bidirectional file transfer (30 MB cap), and JSON-based beaconing to 185.21.14[.]249 and a secondary Finland-hosted node at 157.180.88[.]26. EndRAT persists by writing new .au3 files padded with random garbage and re-registering itself via a BAT file plus schtasks on a 5-10 minute interval. A build-path artifact recovered from the sample ('D:\3_Attack Weapon\Autoit\Build__Poseidon - Manage\client3.3.14.a3x') directly links this activity to the operator's earlier 'Operation Poseidon' campaign (Genians, January 2026), which weaponized Google/Naver ad click-tracking redirection URLs to deliver EndRAT via compromised WordPress sites.
The second payload, RftRAT (delivered as cliconfg.au3), uses SUB-based repeated-key string decoding for obfuscation and beacons to a Japan-hosted C2 at 96.62.214[.]5 over port 443 in an attempt to blend in with legitimate HTTPS traffic. It supports cmd, exit, download, upload, listdir, delete, and run commands. This Japan-based infrastructure correlates with C2 nodes seen in earlier, previously attributed Konni operations, reinforcing attribution confidence.
The third payload, RemcosRAT (delivered as sqlite4.au3), is a commercial-grade RAT (originally marketed by Breaking Security as a legitimate remote administration tool since 2016) repurposed for espionage. Its configuration is stored RC4-encrypted inside the PE resource section (SETTINGS entry under RCData), with the RC4 key length encoded in the first configuration byte (0x99 observed). Remcos beacons to a Netherlands-hosted C2 at 178.16.54[.]208 and provides keylogging, credential/browser data theft, UAC bypass for privilege elevation, process injection/hollowing for defense evasion, and full remote administration (live shell, file manager, registry editor).
Post-compromise, the attacker deployed additional persistence artifacts across the filesystem, including two Startup-folder LNKs (Start_Web.lnk launching C:\ProgramData\NuGetPacks\AutoIt3.exe against mmlib.au3, and SVC_Init.lnk launching C:\Users\Public\etaxSign\AutoIt3.exe against cliconfg.au3), concealed payload directories under C:\ProgramData\Casio\ (sqlite4.au3, svc.exe, taskhosts.exe), C:\ProgramData\Startup\Spoolsv.exe, C:\ProgramData\remcos\logs.dat, and an installed RDP Wrapper under C:\Program Files\ to enable persistent remote desktop access alongside the RAT channels.
The campaign's distinguishing secondary-propagation stage involved the attacker abusing the victim's already-authenticated KakaoTalk PC client session -- rather than compromising KakaoTalk itself -- to selectively message specific contacts from the victim's friend list with a new lure ('North Korea-related video proposal'), weaponizing the implicit trust of the messenger relationship to drive further infections. This technique mirrors prior Kimsuky/Konni abuse of KakaoTalk documented by industry researchers.
Genians attributes the campaign to Konni APT with high confidence based on: reuse of Japan-hosted C2 infrastructure tied to earlier Konni operations; consistent multi-RAT tradecraft (EndRAT/RftRAT/RemcosRAT combined deployment); the 'Poseidon' build-path artifact tying this activity directly to the January 2026 Operation Poseidon campaign; and continuity of social-engineering lures themed around North Korean human rights and government/NGO impersonation, a signature Konni/Kimsuky targeting pattern. Konni (MITRE ATT&CK software S0356) is a North Korea-nexus RAT tool family active since at least 2014 with code overlap to NOKKI, historically associated with APT37 and operating under the broader DPRK Kimsuky (G0094) umbrella of state-sponsored cyber espionage activity targeting South Korean government, NGO, and human-rights-adjacent targets. No CVE applies -- the intrusion chain relies entirely on social engineering and native Windows LNK/PowerShell/AutoIt execution rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1529
Collection
T1005 Data from Local System; T1115 Clipboard Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1055.012 Process Hollowing; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1053.005 Scheduled Task; T1059.001 PowerShell; T1059.007 JavaScript; T1204.002 Malicious File
Persistence
T1053.005 Scheduled Task; T1133 External Remote Services; T1547.001 Registry Run Keys / Startup Folder; T1547.005 Security Support Provider
Credential Access
T1056.001 Keylogging; T1555.003 Credentials from Web Browsers
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573.001 Symmetric Cryptography
Discovery
T1082 System Information Discovery; T1087 Account Discovery
Impact
T1499 Endpoint Denial of Service
Privilege Escalation
T1548.002 Bypass User Account Control
Initial Access
Resource Development
Affected products and versions in Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy
- Microsoft — Windows (LNK/PowerShell/Scheduled Tasks)
Vulnerable versions: All supported Windows versions (social engineering, not a version-specific vulnerability) - Kakao Corp — KakaoTalk PC client
Vulnerable versions: Any version where PC session is already authenticated and locally compromised
Remediation for Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy
Immediate actions
- Block C2 IPs 185.21.14.249, 157.180.88.26, 96.62.214.5, 178.16.54.208 and domain drfeysal.com at perimeter/DNS/proxy
- Hunt for scheduled task named APDNHFU and any 1-minute-interval schtasks created post-archive-extraction
- Hunt for AutoIt3.exe execution with .au3 script arguments outside known-good software inventory
- Search for Startup-folder LNKs Start_Web.lnk and SVC_Init.lnk and ProgramData paths (Casio, NuGetPacks, remcos, Startup\Spoolsv.exe)
- Force logout and re-authenticate all active KakaoTalk PC sessions on potentially affected endpoints; warn users about unsolicited North Korea/human-rights themed lures shared via messenger
- Search mail gateway logs for ZIP attachments containing LNK files with document icons themed around lecturer appointment notices
Workarounds
- Disable Windows Script Host and restrict LNK execution from removable/archived sources via Group Policy where feasible
- Enable PowerShell Constrained Language Mode and Script Block Logging to increase visibility into the SysWOW64 PowerShell stage
Longer-term hardening
- Deploy EDR with behavioral detection tuned to LNK-spawns-PowerShell-spawns-AutoIt chains rather than static hash/IOC matching
- Restrict or monitor AutoIt3.exe execution via application allowlisting given its recurring abuse as a loader by this actor
- Implement DMARC/DKIM/SPF enforcement and attachment sandboxing for inbound email, especially ZIP/LNK combinations
- Deploy network detection for the custom endServer9688/endClient9688 socket protocol and non-standard TLS handshakes on port 443
- Establish organizational policy restricting execution of messenger-shared files without verification, given the KakaoTalk secondary-propagation vector
Timeline of Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy
- Prior reporting documents Kimsuky/Konni-linked actors abusing KakaoTalk and targeting South Korean Android devices with remote wipe tactics, establishing precedent for messenger-abuse tradecraft.
- Genians publishes Operation Poseidon report detailing Konni APT abuse of Google/Naver ad click-tracking redirection to deliver EndRAT via compromised WordPress sites, establishing the build-lineage later found in this campaign.
- Estimated window of active spear-phishing delivery of the 'North Korean human rights lecturer' appointment lure prior to Genians' public report.
- SysWOW64 PowerShell launched via cmd.exe downloads AutoIt3.exe interpreter and APDNHFU.pdf (EndRAT A3X payload) from drfeysal[.]com C2.
- Victims receive spear-phishing email with ZIP attachment containing malicious LNK disguised as a document; execution triggers self-locating XOR-decoded payload extraction.
- EndRAT establishes custom-protocol beaconing over port 80 to 185.21.14[.]249 (and 157.180.88[.]26), enabling remote shell and file transfer.
- Scheduled Task 'APDNHFU' created with 1-minute recurrence over 365 days; original LNK self-deletes to remove forensic trace.
- RemcosRAT (sqlite4.au3) deployed with RC4-encrypted configuration, beaconing to Netherlands-hosted C2 178.16.54[.]208; keylogging and credential theft begin.
- RftRAT (cliconfg.au3) deployed with SUB-obfuscated strings, beaconing to Japan-hosted C2 96.62.214[.]5 over port 443.
- Attacker abuses victim's authenticated KakaoTalk PC session to message selected contacts with a new 'North Korea-related video proposal' lure, propagating the campaign through trusted relationships.
- Genians Security Center publishes technical report attributing the campaign to Konni APT and disclosing IOCs, TTPs, and the KakaoTalk abuse vector.
Sources cited for Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy
- Genians: Konni APT KakaoTalk-Linked Spear-Phishing Campaign
- Genians: Operation Poseidon - Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms
- MITRE ATT&CK: KONNI (Software S0356)
- MITRE ATT&CK: Kimsuky (Group G0094)
- SecurityOnline: Operation Poseidon - Konni APT Hijacks Google & Naver Ads for Malware
- UPI: North Korea-linked hackers pose as human rights activists, report says
- Paubox: Google Ads abused in targeted campaign delivering EndRAT malware
- SOC Prime: Operation Poseidon - LNK Phishing via Ads Redirects
- Elastic Security Labs: Dissecting REMCOS RAT Part One
- Point Wild: Remcos Revisited - Inside the RAT's Evolving Command-and-Control Techniques
- Dark Reading: Kimsuky Pwns South Korean Androids, Abuses KakaoTalk
- CISA: North Korean Advanced Persistent Threat Focus - Kimsuky (AA20-301A)
- Check Point: Remcos Malware Overview
Detection coverage for TL-2026-1529
As of 2026-03-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1529 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.