# Operation Poseidon: Konni APT Spear-Phishing Campaign Abusing Google Ads Redirection to Deliver EndRAT

> Konni APT (North Korea, RGB-linked, overlaps with Kimsuky) is running 'Operation Poseidon,' a spear-phishing campaign impersonating South Korean financial institutions and North Korean human rights NGOs that abuses legitimate Google Ads (doubleclick.net) and NAVER Marketing redirection infrastructure to deliver LNK-in-ZIP files. The LNK triggers AutoIt3.exe to load the memory-resident EndRAT (AutoItRAT variant) implant, using invisible-text email padding and web-beacon tracking for evasion and recipient telemetry.

- **Published:** 2026-01-19T00:00:00Z
- **Last reviewed:** 2026-01-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1531
- **ID:** TL-2026-1531
- **Severity:** CRITICAL
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Konni APT (North Korea)
- **Detections:** 9 · **IOCs:** 50 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Genians Security Center identified Operation Poseidon, an ongoing Konni APT campaign targeting South Korean financial-sector employees and North Korean human-rights activists/NGOs. The threat actor sends spear-phishing emails, spoofed via PHPMailer, that impersonate financial institutions (with lures such as 'explanatory materials,' 'remittance confirmation,' 'transaction details,' and 'personal information consent' requests) and NK human-rights recruitment/outreach communications. Emails contain CSS 'display:none' hidden English-language padding sentences designed to defeat AI/LLM-based content-classification detection, plus 1x1-pixel image web beacons with Base64-encoded per-recipient identifiers to confirm opens and track engagement.

Malicious download links are wrapped through Google Ads' ad.doubleclick.net redirection mechanism (and, in a smaller May-July 2025 subset, NAVER's mkt.naver.com marketing redirector) so that the true destination — attacker or compromised WordPress infrastructure — is hidden inside legitimate advertising-network URL parameters, defeating simple domain-reputation and URL-category filtering. Clicking the link downloads a ZIP archive containing a Windows LNK (shortcut) file whose icon is masqueraded as a PDF document. Executing the LNK invokes AutoIt3.exe with an embedded AutoIt script and PowerShell, which loads the EndRAT payload directly into memory without dropping additional stages to disk, evading signature-based antivirus.

EndRAT (tracked by Genians as EndRAT / AutoItRAT) is a memory-resident remote access trojan. Internal strings recovered from samples (endServer9688, endClient9688, endServerFile9688, endClientFile9688) and a build-path artifact — 'D:\3_Attack Weapon\Autoit\Build\__Poseidon - Attack\client3.3.14.a3x' — reveal the operator's internal campaign codename ('Poseidon - Attack') and a maintained versioning scheme (client3.3.14), indicating continuous development of a reusable AutoIt-based attack framework rather than a one-off toolset.

Attribution to Konni rests on: reuse of the C2 domain jlrandsons.co.uk across multiple campaigns; identical delivery/attack code shared between the financial-lure and human-rights-lure tracks; a malware family (EndRAT/AutoItRAT) whose versioning is consistent with historical Konni AutoIt-based RAT development; abuse of compromised WordPress sites for staging/C2 matching prior Konni tradecraft; and thematic targeting (South Korean finance, North Korean human-rights circles) that aligns with Konni's documented social-engineering patterns. Konni overlaps significantly with the broader Kimsuky cluster (MITRE ATT&CK G0094; aliases Black Banshee, Velvet Chollima, THALLIUM, Emerald Sleet, APT43, TA427, Springtail, Earth Kumiho, TA406, Vedalia, Earth Imp), a DPRK Reconnaissance General Bureau (RGB)-attributed espionage group active since at least 2012.

Genians assesses the campaign as CRITICAL severity and 'difficult to mitigate through a single security solution,' recommending layered, behavior-based EDR defense (process-tree monitoring from document viewers to cmd.exe/powershell.exe/AutoIt3.exe, PowerShell network-egress monitoring, and Attack Storyline-style infection-chain correlation) rather than reliance on signature or URL-reputation controls alone.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1587 Develop Capabilities
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1027 Obfuscated Files or Information
- T1082 System Information Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1102 Web Service
- T1021 Remote Services
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1598 Phishing for Information
- T1047 Windows Management Instrumentation
- T1574 Hijack Execution Flow

## Sources

- [Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms](https://www.genians.co.kr/en/blog/threat_intelligence/spear-phishing)
- [Kimsuky, Black Banshee, Velvet Chollima, Emerald Sleet, THALLIUM, APT43, TA427, Springtail, Earth Kumiho, PatheticSlug, Group G0094](https://attack.mitre.org/groups/G0094/)
- [North Korean Advanced Persistent Threat Focus: Kimsuky](https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-301a)
- [North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress](https://thehackernews.com/2025/05/north-korean-konni-apt-targets-ukraine.html)
- [North Korea-linked Konni APT used Google Find Hub to erase data and spy on defectors](https://securityaffairs.com/184474/intelligence/north-korea-konni-apt-used-google-find-hub-to-erase-data-and-spy-on-defectors.html)
- [Threat Assessment: North Korean Threat Groups](https://unit42.paloaltonetworks.com/threat-assessment-north-korean-threat-groups-2024/)
- [Konni Group Attack Detection: North Korean Hackers Leverage Russian-Language Weaponized Word Document to Spread RAT Malware](https://socprime.com/blog/konni-group-attack-detection-north-korean-hackers-leverage-russian-language-weaponized-word-document-to-spread-rat-malware/)
- [Threat Intelligence Report: Analysis of the LNK Malware Threat from Nation-State Hacking Groups](https://www.fsec.or.kr/bbs/detail?menuNo=244&bbsNo=11839)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1531
