Threat reportPhishingTL-2026-1531
Operation Poseidon: Konni APT Spear-Phishing Campaign Abusing Google Ads Redirection to Deliver EndRAT
Operation Poseidon (TL-2026-1531), also tracked as Operation Poseidon, is a critical-severity phishing campaign, first published 2026-01-19. It is attributed to Konni APT (North Korea) with high confidence, affects Microsoft Windows (LNK shortcut file handling / Windows Script Host, maps to 22 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 50 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 22MITRE ATT&CK
- Actors
- 1Konni APT
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 50Indicators of compromise
Key facts for TL-2026-1531
- Threat ID
- TL-2026-1531
- Also known as
- Operation Poseidon
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution
- Konni APT
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- financial services, government administration, human rights ngo, banking
- Target regions
- south korea, East Asia
- Detection rules
- 9
- Indicators of compromise
- 50
Malware and tooling in Operation Poseidon
Malware and tooling: AutoItRAT, EndRAT, AutoIt3.exe
How Operation Poseidon works
Konni APT (North Korea, RGB-linked, overlaps with Kimsuky) is running 'Operation Poseidon,' a spear-phishing campaign impersonating South Korean financial institutions and North Korean human rights NGOs that abuses legitimate Google Ads (doubleclick.net) and NAVER Marketing redirection infrastructure to deliver LNK-in-ZIP files. The LNK triggers AutoIt3.exe to load the memory-resident EndRAT (AutoItRAT variant) implant, using invisible-text email padding and web-beacon tracking for evasion and recipient telemetry.
Genians Security Center identified Operation Poseidon, an ongoing Konni APT campaign targeting South Korean financial-sector employees and North Korean human-rights activists/NGOs. The threat actor sends spear-phishing emails, spoofed via PHPMailer, that impersonate financial institutions (with lures such as 'explanatory materials,' 'remittance confirmation,' 'transaction details,' and 'personal information consent' requests) and NK human-rights recruitment/outreach communications. Emails contain CSS 'display:none' hidden English-language padding sentences designed to defeat AI/LLM-based content-classification detection, plus 1x1-pixel image web beacons with Base64-encoded per-recipient identifiers to confirm opens and track engagement.
Malicious download links are wrapped through Google Ads' ad.doubleclick.net redirection mechanism (and, in a smaller May-July 2025 subset, NAVER's mkt.naver.com marketing redirector) so that the true destination — attacker or compromised WordPress infrastructure — is hidden inside legitimate advertising-network URL parameters, defeating simple domain-reputation and URL-category filtering. Clicking the link downloads a ZIP archive containing a Windows LNK (shortcut) file whose icon is masqueraded as a PDF document. Executing the LNK invokes AutoIt3.exe with an embedded AutoIt script and PowerShell, which loads the EndRAT payload directly into memory without dropping additional stages to disk, evading signature-based antivirus.
EndRAT (tracked by Genians as EndRAT / AutoItRAT) is a memory-resident remote access trojan. Internal strings recovered from samples (endServer9688, endClient9688, endServerFile9688, endClientFile9688) and a build-path artifact — 'D:\3_Attack Weapon\Autoit\Build\__Poseidon - Attack\client3.3.14.a3x' — reveal the operator's internal campaign codename ('Poseidon - Attack') and a maintained versioning scheme (client3.3.14), indicating continuous development of a reusable AutoIt-based attack framework rather than a one-off toolset.
Attribution to Konni rests on: reuse of the C2 domain jlrandsons.co.uk across multiple campaigns; identical delivery/attack code shared between the financial-lure and human-rights-lure tracks; a malware family (EndRAT/AutoItRAT) whose versioning is consistent with historical Konni AutoIt-based RAT development; abuse of compromised WordPress sites for staging/C2 matching prior Konni tradecraft; and thematic targeting (South Korean finance, North Korean human-rights circles) that aligns with Konni's documented social-engineering patterns. Konni overlaps significantly with the broader Kimsuky cluster (MITRE ATT&CK G0094; aliases Black Banshee, Velvet Chollima, THALLIUM, Emerald Sleet, APT43, TA427, Springtail, Earth Kumiho, TA406, Vedalia, Earth Imp), a DPRK Reconnaissance General Bureau (RGB)-attributed espionage group active since at least 2012.
Genians assesses the campaign as CRITICAL severity and 'difficult to mitigate through a single security solution,' recommending layered, behavior-based EDR defense (process-tree monitoring from document viewers to cmd.exe/powershell.exe/AutoIt3.exe, PowerShell network-egress monitoring, and Attack Storyline-style infection-chain correlation) rather than reliance on signature or URL-reputation controls alone.
MITRE ATT&CK techniques used in TL-2026-1531
Collection
lateral-movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer
Discovery
T1082 System Information Discovery
Persistence
T1547 Boot or Logon Autostart Execution
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1598 Phishing for Information
Affected products and versions in Operation Poseidon
- Microsoft — Windows (LNK shortcut file handling / Windows Script Host ecosystem)
Vulnerable versions: All supported Windows desktop versions - AutoIt Consulting — AutoIt3.exe interpreter (abused as living-off-the-land execution vector)
Vulnerable versions: Any version present on victim endpoints - Google — Google Ads / ad.doubleclick.net redirection service (abused as URL-hiding infrastructure)
Vulnerable versions: N/A - service abuse, not a vulnerability - NAVER Corporation — NAVER Marketing / mkt.naver.com redirector (abused, limited May-July 2025)
Vulnerable versions: N/A - service abuse, not a vulnerability
Remediation for Operation Poseidon
Immediate actions
- Block or quarantine by default any inbound attachments/links from senders impersonating financial institutions or NGO/human-rights outreach
- Apply warning banners for attachments/filenames containing keywords such as 'explanatory materials,' 'remittance confirmation,' 'transaction details,' or 'personal information consent'
- Disable or strip LNK files packaged inside ZIP archives at the email gateway and endpoint
- Block known C2 domains and IPs (see IOC list) at DNS/firewall/proxy
- Hunt for AutoIt3.exe execution originating from Temp/Downloads paths or spawned by explorer.exe following LNK execution
Workarounds
- Strengthen behavior-based detection for post-click redirection flows traversing legitimate advertising domains (ad.doubleclick.net, mkt.naver.com)
- Classify archive/executable downloads reached via advertising-network redirect URLs as anomalous and subject to additional inspection or blocking
- Disable inline image loading / web-beacon rendering in email clients to reduce recipient-tracking telemetry leakage
Longer-term hardening
- Deploy behavior-based EDR with process-tree analytics for document-viewer-to-shell transitions
- Correlate AV signatures, IOC feeds, and machine-learning/XBA behavioral engines to detect multi-stage infection flows
- Implement Attack Storyline-style visualization to trace full infection chains from initial email to C2
- Monitor PowerShell network egress for anomalous external connections outside normal administrative baselines
- Establish automatic endpoint isolation policies for hosts exhibiting fileless C2 behavior
Timeline of Operation Poseidon
- Limited abuse of NAVER Marketing (mkt.naver.com) click-tracking/redirection infrastructure begins as an early precursor delivery vector, observed on a limited basis May-July 2025.
- Attack pattern shifts to using marketing/advertising URL intermediaries as the primary delivery mechanism; EndRAT/AutoItRAT malware samples are first reported by researchers, marking the pivot from NAVER-only abuse to broader advertising-redirector abuse.
- Konni shifts primary delivery infrastructure to abuse of Google Ads (ad.doubleclick.net) redirection to conceal C2 destinations within legitimate advertising URL parameters, superseding the earlier NAVER-only redirection chain.
- Spear-phishing wave impersonating South Korean financial institutions begins; ZIP archives containing malicious LNK files are distributed to financial-sector employees, dropping EndRAT via AutoIt3.exe.
- A parallel campaign track impersonating North Korean human-rights NGO recruitment/outreach communications is identified, sharing identical attack code and infrastructure with the financial-lure track.
- South Korea's Financial Security Institute (FSI) publishes 'Threat Intelligence Report: Analysis of the LNK Malware Threat from Nation-State Hacking Groups,' a comparative analysis of the LNK-based malware used in the campaign (fsec.or.kr).
- Operators begin stripping the internal build-path artifact ('D:\3_Attack Weapon\Autoit\Build\__Poseidon - Attack\client3.3.14.a3x') from newer EndRAT samples, indicating awareness of and adaptation to prior detection/disclosure of the string.
- Genians Security Center publicly discloses Operation Poseidon, detailing the full attack chain, EndRAT/AutoItRAT malware internals, web-beacon/CSS-padding evasion tradecraft, and associated IOCs.
Sources cited for Operation Poseidon
- Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms
- Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Group G0094
- North Korean Advanced Persistent Threat Focus: Kimsuky
- North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress
- North Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors
- Threat Assessment: North Korean Threat Groups
- Konni Group Attack Detection: North Korean Hackers Leverage Russian-Language Weaponized Word Document to Spread RAT Malware
- Threat Intelligence Report: Analysis of the LNK Malware Threat from Nation-State Hacking Groups
Detection coverage for TL-2026-1531
As of 2026-01-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1531 across Splunk SPL, Microsoft KQL and Sigma, covering 50 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1531
15 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.