HomeSecurityKonni hackers use AI-generated PowerShell backdoor

Konni hackers use AI-generated PowerShell backdoor

North Korean hackers Konni are using PowerShell malware, created with artificial intelligence (AI) tools, to target developers and engineering teams in the blockchain.

Konni hackers use AI-generated PowerShell backdoor

According to Check Point Research, the new phishing campaign has targeted Japan, Australia, and India, expanding the group's reach beyond South Korea, Russia, Ukraine, and European countries.

Konni hackers

Konni has been active since at least 2014 and is primarily known for targeting organizations and individuals in South Korea. It is also tracked as Earth Imp, Opal Sleet, Osmium, TA406, and Vedalia.

See also: Gmail, Facebook, Instagram, TikTok credentials leaked online

In November 2025, Genians Security Center (GSC) analyzed the group's attacks on Android. The attack exploited Google's asset tracking service, Find Hub, to remotely reset victims' devices and erase personal data from them.

New phishing attacks

North Korean hackers Konni are sending spear-phishing emails containing malicious links disguised as harmless advertising URLs (related to Google and Naver advertising platforms). The goal is to bypass security filters and deliver a remote access Trojan codenamed EndRAT.

Konni hackers use AI-generated PowerShell backdoor

The malicious campaign is being tracked as Operation Poseidon by GSC, with the attacks impersonating North Korean human rights organizations and financial institutions in South Korea. The attacks are characterized by the use of improperly secured WordPress websites to distribute malware and for command and control (C2) infrastructure.

The emails are disguised as financial notifications, such as transaction confirmations or money transfer requests, to trick recipients into downloading ZIP files hosted on WordPress websites. The ZIP file includes a Windows shortcut (LNK) designed to run an AutoIt script disguised as a PDF. The AutoIt script is a known piece of Konni malware called EndRAT.

“This attack is analyzed as a case that effectively bypasses email security filtering and user vigilance through a spear-phishing channel that exploits the ad click redirection mechanism used in Google’s advertising ecosystem,” the South Korean security firm said.

See also: New sneaky phishing campaign targets Marriott & Microsoft customers

“It was confirmed that the attacker used the redirect URL structure of a domain used for ad click tracking (ad.doubleclick[.]net) to gradually direct users to external infrastructure where actual malicious files were hosted.“.

How exactly does the attack work?

The latest campaign, documented by Check Point, leverages ZIP files that mimic legitimate documents and are hosted on Discord's content delivery network (CDN) (to launch a multi-layered attack chain). The exact initial access channel used in the attacks is unknown.

The ZIP file contains a decoy PDF and an LNK file. The shortcut file launches a built-in PowerShell loader that extracts two additional files, a decoy Microsoft Word document and a CAB file, displaying the Word document as a distraction mechanism.

The shortcut file extracts the contents of the CAB file, which contains a PowerShell backdoor, two batch scripts, and an executable used to bypass User Account Control (UAC). The first batch script is used to prepare the environment, establish persistence via a scheduled task, deploy the backdoor , and execute it (after which it is deleted from disk to reduce analysis visibility).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The PowerShell backdoor performs a series of anti-analysis and sandbox-evasion checks, profiles the system, and attempts to escalate privileges using the FodHelper UAC. The backdoor cleans up the previously installed UAC bypass executable, configures a Microsoft Defender for “C:\ProgramData”, and runs the second batch script to replace the previously created scheduled task with a new one that can be run with elevated privileges.

See also: Multi-stage Phishing Campaign Targets Russia with Amnesia RAT

The backdoor also installs SimpleHelp, a legitimate Remote Monitoring and Management (RMM) tool for permanent remote access. It also communicates with a C2 server, protected by an encryption gate, which is intended to block non-browser traffic to periodically send host metadata and execute PowerShell code returned by the server.

The cybersecurity firm said there is evidence that the PowerShell backdoor was created with the help of an AI tool.

“Rather than focusing on individual end users, the campaign’s goal appears to be to establish a foothold in development environments, where a breach can provide broader access to multiple projects and services,” Check Point said. “The introduction of AI-assisted tools suggests an effort to accelerate development and standardize code, while continuing to rely on proven delivery methods and social engineering.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS