# Konni APT Spear-Phishing Campaign Abuses KakaoTalk to Deploy EndRAT, RftRAT, RemcosRAT

> The North Korea-linked Konni APT group ran a spear-phishing campaign disguised as a North Korean human rights lecturer appointment notice, delivering a self-locating malicious LNK file inside a ZIP archive that deploys EndRAT, RftRAT, and RemcosRAT. Attackers then hijacked victims' compromised KakaoTalk PC sessions to redistribute the lure to trusted contacts, achieving worm-like secondary propagation.

- **Published:** 2026-03-16T00:00:00Z
- **Last reviewed:** 2026-03-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1529
- **ID:** TL-2026-1529
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Konni APT (North Korea)
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Genians Security Center (GSC) identified a multi-stage Konni APT campaign that begins with a spear-phishing email disguised as an official notice appointing the recipient as a 'North Korean human rights lecturer.' The email delivers a ZIP archive containing a malicious LNK (Windows shortcut) file masquerading with a document icon. The LNK uses a self-locating mechanism keyed to a fixed file size constant (0x001DBB82 / 1,948,546 bytes) to find and decode an embedded, XOR-encoded (key 0x3D) payload stored at offset 0x1892 (size 0x1D79FB bytes) within itself. Execution proceeds through 32-bit PowerShell (SysWOW64) launched via cmd.exe, which downloads a second-stage AutoIt3.exe interpreter and an AutoIt-compiled payload (APDNHFU.pdf, actually an A3X script container) from the attacker's WordPress-based C2 at drfeysal[.]com. Persistence is established via a Scheduled Task named 'APDNHFU' that re-triggers every minute for 365 days, and the original LNK deletes itself post-execution as an anti-forensic measure, leaving behind a decoy PDF.

The first payload, EndRAT, is an AutoIt-compiled (A3X) implant using dummy ASCII prefix/suffix padding to defeat signature-based detection. It communicates over TCP port 80 using a custom application-layer protocol (not real HTTP) framed with 'endServer9688'/'endClient9688' delimiters, and supports file management, remote shell, bidirectional file transfer (30 MB cap), and JSON-based beaconing to 185.21.14[.]249 and a secondary Finland-hosted node at 157.180.88[.]26. EndRAT persists by writing new .au3 files padded with random garbage and re-registering itself via a BAT file plus schtasks on a 5-10 minute interval. A build-path artifact recovered from the sample ('D:\3_Attack Weapon\Autoit\Build__Poseidon - Manage\client3.3.14.a3x') directly links this activity to the operator's earlier 'Operation Poseidon' campaign (Genians, January 2026), which weaponized Google/Naver ad click-tracking redirection URLs to deliver EndRAT via compromised WordPress sites.

The second payload, RftRAT (delivered as cliconfg.au3), uses SUB-based repeated-key string decoding for obfuscation and beacons to a Japan-hosted C2 at 96.62.214[.]5 over port 443 in an attempt to blend in with legitimate HTTPS traffic. It supports cmd, exit, download, upload, listdir, delete, and run commands. This Japan-based infrastructure correlates with C2 nodes seen in earlier, previously attributed Konni operations, reinforcing attribution confidence.

The third payload, RemcosRAT (delivered as sqlite4.au3), is a commercial-grade RAT (originally marketed by Breaking Security as a legitimate remote administration tool since 2016) repurposed for espionage. Its configuration is stored RC4-encrypted inside the PE resource section (SETTINGS entry under RCData), with the RC4 key length encoded in the first configuration byte (0x99 observed). Remcos beacons to a Netherlands-hosted C2 at 178.16.54[.]208 and provides keylogging, credential/browser data theft, UAC bypass for privilege elevation, process injection/hollowing for defense evasion, and full remote administration (live shell, file manager, registry editor).

Post-compromise, the attacker deployed additional persistence artifacts across the filesystem, including two Startup-folder LNKs (Start_Web.lnk launching C:\ProgramData\NuGetPacks\AutoIt3.exe against mmlib.au3, and SVC_Init.lnk launching C:\Users\Public\etaxSign\AutoIt3.exe against cliconfg.au3), concealed payload directories under C:\ProgramData\Casio\ (sqlite4.au3, svc.exe, taskhosts.exe), C:\ProgramData\Startup\Spoolsv.exe, C:\ProgramData\remcos\logs.dat, and an installed RDP Wrapper under C:\Program Files\ to enable persistent remote desktop access alongside the RAT channels.

The campaign's distinguishing secondary-propagation stage involved the attacker abusing the victim's already-authenticated KakaoTalk PC client session -- rather than compromising KakaoTalk itself -- to selectively message specific contacts from the victim's friend list with a new lure ('North Korea-related video proposal'), weaponizing the implicit trust of the messenger relationship to drive further infections. This technique mirrors prior Kimsuky/Konni abuse of KakaoTalk documented by industry researchers.

Genians attributes the campaign to Konni APT with high confidence based on: reuse of Japan-hosted C2 infrastructure tied to earlier Konni operations; consistent multi-RAT tradecraft (EndRAT/RftRAT/RemcosRAT combined deployment); the 'Poseidon' build-path artifact tying this activity directly to the January 2026 Operation Poseidon campaign; and continuity of social-engineering lures themed around North Korean human rights and government/NGO impersonation, a signature Konni/Kimsuky targeting pattern. Konni (MITRE ATT&CK software S0356) is a North Korea-nexus RAT tool family active since at least 2014 with code overlap to NOKKI, historically associated with APT37 and operating under the broader DPRK Kimsuky (G0094) umbrella of state-sponsored cyber espionage activity targeting South Korean government, NGO, and human-rights-adjacent targets. No CVE applies -- the intrusion chain relies entirely on social engineering and native Windows LNK/PowerShell/AutoIt execution rather than a software vulnerability.

## MITRE ATT&CK

- T1566.002 Spearphishing Link
- T1059.001 PowerShell
- T1059.007 JavaScript
- T1053.005 Scheduled Task
- T1204.002 Malicious File
- T1547.001 Registry Run Keys / Startup Folder
- T1547.005 Security Support Provider
- T1053.005 Scheduled Task
- T1133 External Remote Services
- T1548.002 Bypass User Account Control
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1055.012 Process Hollowing
- T1070.004 File Deletion
- T1036.005 Match Legitimate Resource Name or Location
- T1056.001 Keylogging
- T1555.003 Credentials from Web Browsers
- T1087 Account Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1115 Clipboard Data
- T1105 Ingress Tool Transfer
- T1071.001 Web Protocols
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography
- T1041 Exfiltration Over C2 Channel
- T1499 Endpoint Denial of Service
- T1584.004 Server
- T1583.008 Malvertising

## Sources

- [Genians: Konni APT KakaoTalk-Linked Spear-Phishing Campaign](https://www.genians.co.kr/en/blog/threat_intelligence/kakaotalk)
- [Genians: Operation Poseidon - Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms](https://www.genians.co.kr/en/blog/threat_intelligence/spear-phishing)
- [MITRE ATT&CK: KONNI (Software S0356)](https://attack.mitre.org/software/S0356/)
- [MITRE ATT&CK: Kimsuky (Group G0094)](https://attack.mitre.org/groups/G0094/)
- [SecurityOnline: Operation Poseidon - Konni APT Hijacks Google & Naver Ads for Malware](https://securityonline.info/operation-poseidon-konni-apt-hijacks-google-naver-ads-for-malware/)
- [UPI: North Korea-linked hackers pose as human rights activists, report says](https://www.upi.com/Top_News/World-News/2026/01/19/North-Korea-hackers-Konni-spear-phishing-APT-Genians/5761768807686/)
- [Paubox: Google Ads abused in targeted campaign delivering EndRAT malware](https://www.paubox.com/blog/google-ads-abused-in-targeted-campaign-delivering-endrat-malware)
- [SOC Prime: Operation Poseidon - LNK Phishing via Ads Redirects](https://socprime.com/active-threats/operation-poseidon-analysis/)
- [Elastic Security Labs: Dissecting REMCOS RAT Part One](https://www.elastic.co/security-labs/dissecting-remcos-rat-part-one)
- [Point Wild: Remcos Revisited - Inside the RAT's Evolving Command-and-Control Techniques](https://www.pointwild.com/threat-intelligence/remcos-revisited-inside-the-rats-evolving-command-and-control-techniques/)
- [Dark Reading: Kimsuky Pwns South Korean Androids, Abuses KakaoTalk](https://www.darkreading.com/remote-workforce/kimsuky-apt-south-korean-androids-abuses-kakaotalk)
- [CISA: North Korean Advanced Persistent Threat Focus - Kimsuky (AA20-301A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a)
- [Check Point: Remcos Malware Overview](https://www.checkpoint.com/cyber-hub/threat-prevention/what-is-malware/remcos-malware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1529
