Operation Poseidon: Konni APT Spear-Phishing Campaign Abusing Google Ads Redirection to Deliver EndRAT — Threadlinqs Intelligence
As of 2026-01-19, Operation Poseidon: Konni APT Spear-Phishing Campaign Abusing Google Ads Redirection to Deliver EndRAT is a critical-severity phishing threat attributed to Konni APT (North Korea), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 50 indicators of compromise.
Threat ID: TL-2026-1531 · Severity: CRITICAL · Status: ACTIVE · Category: PHISHING
Attribution: Konni APT · North Korea · ESPIONAGE
Konni APT (North Korea, RGB-linked, overlaps with Kimsuky) is running 'Operation Poseidon,' a spear-phishing campaign impersonating South Korean financial institutions and North Korean human rights
Genians Security Center identified Operation Poseidon, an ongoing Konni APT campaign targeting South Korean financial-sector employees and North Korean human-rights activists/NGOs. The threat actor sends spear-phishing emails, spoofed via PHPMailer, that impersonate financial institutions (with lures such as 'explanatory materials,' 'remittance confirmation,' 'transaction details,' and 'personal information consent' requests) and NK human-rights recruitment/outreach communications. Emails contain CSS 'display:none' hidden English-language padding sentences designed to defeat AI/LLM-based content-classification detection, plus 1x1-pixel image web beacons with Base64-encoded per-recipient identifiers to confirm opens and track engagement.
Malicious download links are wrapped through Google Ads' ad.doubleclick.net redirection mechanism (and, in a smaller May-July 2025 subset, NAVER's mkt.naver.com marketing redirector) so that the true destination — attacker or compromised WordPress infrastructure — is hidden inside legitimate advertising-network URL parameters, defeating simple domain-reputation and URL-category filtering. Clicking the link downloads a ZIP archive containing a Windows LNK (shortcut) file whose icon is masqueraded as a PDF document. Executing the LNK invokes AutoIt3.exe with an embedded AutoIt script and PowerShell, which loads the EndRAT payload directly into memory without dropping additional stages to disk, evading signature-based antivirus.
EndRAT (tracked by Genians as EndRAT / AutoItRAT) is a memory-resident remote access trojan. Internal strings recovered from samples (endServer9688, endClient9688, endServerFile9688, endClientFile9688) and a build-path artifact — 'D:\3_Attack Weapon\Autoit\Build\__Poseidon - Attack\client3.3.14.a3x' — reveal the operator's internal campaign codename ('Poseidon - Attack') and a maintained versioning scheme (client3.3.14), indicating continuous development of a reusable AutoIt-based attack framework rather than a one-off toolset.
Attribution to Konni rests on: reuse of the C2 domain jlrandsons.co.uk across multiple campaigns; identical delivery/attack code shared between the financial-lure and human-rights-lure tracks; a malware family (EndRAT/AutoItRAT) whose versioning is consistent with historical Konni AutoIt-based RAT development; abuse of compromised WordPress sites for staging/C2 matching prior Konni tradecraft; and thematic targeting (South Korean finance, North Korean human-rights circles) that aligns with Konni's documented social-engineering patterns. Konni overlaps significantly with the broader Kimsuky cluster (MITRE ATT&CK G0094; aliases Black Banshee, Velvet Chollima, THALLIUM, Emerald Sleet, APT43, TA427, Springtail, Earth Kumiho, TA406, Vedalia, Earth Imp), a DPRK Reconnaissance General Bureau (RGB)-attributed espionage group active since at least 2012.
Genians assesses the campaign as CRITICAL severity and 'difficult to mitigate through a single security solution,' recommending layered, behavior-based EDR defense (process-tree monitoring from document viewers to cmd.exe/powershell.exe/AutoIt3.exe, PowerShell network-egress monitoring, and Attack Storyline-style infection-chain correlation) rather than reliance on signature or URL-reputation controls alone.
Target sectors: financial services, government administration, human rights ngo, banking
Target regions: south korea, East Asia
References
- Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms
- Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Group G0094
- North Korean Advanced Persistent Threat Focus: Kimsuky
- North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress
- North Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors
- Threat Assessment: North Korean Threat Groups
- Konni Group Attack Detection: North Korean Hackers Leverage Russian-Language Weaponized Word Document to Spread RAT Malware
- Threat Intelligence Report: Analysis of the LNK Malware Threat from Nation-State Hacking Groups
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 50 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
15 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
PHISHING, CRITICAL, threat intelligence, cybersecurity, T1589, T1583, T1584, T1587, T1566, T1566, T1204, T1204, T1059, T1059