Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures

Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs.

Recently, the SOCRadar Threat Research Unit (STRU) uncovered Operation Conflict Compass, a targeted campaign by the DPRK-aligned actor Konni, aimed at gathering intelligence on the ongoing trajectory of the Russian invasion of Ukraine.

Key points: 

  • Spear-phishing ZIPs with LNK files disguised as PDFs, using Russia-Ukraine peace framework. Targeting potentially points to diplomatic entities, think tanks, and NGOs.
  • The chain sets up a scheduled task that runs a PowerShell downloader STRU named VelvetCake every minute. It keeps almost no capability on the host, pulling and running server-side scripts on demand, then wiping its artifacts.
  • A recovered second-stage script performs host enumeration and screen capture, exfiltrated over HTTP POST.
  • The same components were also delivered via a trojanized Zoom installer.
  • Attribution to Konni is moderate confidence: targeting, VelvetCake code characteristics, shared C2 and GitHub staging infrastructure, and operator time zone. 

For full details, the research can be read here: https://socradar.io/blog/operation-conflict-compass-konni-ukraine-lnk-lure/

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading