The Konni Group, a well-known hacker group linked to North Korea, is exploiting the KakaoTalk to spread the EndRAT malware to selected contacts of its victims. The new attack begins with spear-phishing emails posing as recruitment notices for North Korean human rights teaching positions.
See also: Konni malware: Distributed via phishing emails and targets Russian users

According to Genians Security Center (GSC), initial access is achieved via a spear-phishing email disguised as an official notification. After a successful attack, the victim executes a malicious LNK file, resulting in infection with remote access malware. The malware remains hidden and persistent on the victim's system for an extended period, stealing internal documents and sensitive information.
Konni Group maintains access to the compromised computer for an extended period, using the unauthorized access to extract internal documents and exploiting the KakaoTalk to selectively spread malware to specific contacts. This attack is notable for exploiting the trust associated with compromised victims to deceive and entrap additional targets.
This is not the first time Konni has used the messaging app as a distribution vector. In November 2025 , the group was found abusing connected sessions on the KakaoTalk chat app to send malicious payloads to victims' contacts in the form of a ZIP file , while simultaneously initiating a remote wipe of their Android devices using stolen Google credentials .
Technical Details of the Konni Group Attack
The latest attack campaign began with a spear-phishing email designed to trick recipients into opening an attached ZIP file containing a Windows shortcut (LNK). When executed, the LNK file downloads a next-stage payload from an external server, installs persistence using scheduled tasks , and ultimately executes the malware while displaying a PDF document to the user as a distraction.
The downloaded malware, written in AutoIt, is a remote access trojan (RAT) named EndRAT (also known as EndClient RAT), which allows the operator to remotely control the compromised computer through capabilities such as file management, remote shell, data transfer, and persistence.
See also: Konni hackers use AI-generated PowerShell backdoor

Further analysis of the infected computer revealed several malicious artifacts, including AutoIt scripts corresponding to RftRAT and RemcosRAT, indicating that the adversary considered the victim valuable enough to deploy multiple RAT for improved resilience.
A key aspect of the attack is the threat actor's abuse of KakaoTalk installed on the infected system to distribute malicious files in the form of ZIP archives to other people in their contact list, effectively turning existing victims into intermediaries for further attacks.
Genians Security Center assessed this campaign as a multi-stage attack operation that goes beyond simple spear-phishing, combining long-term persistence, information theft, and account-based redistribution. The attacker selected certain contacts from the victim's friends list and sent them additional malicious files, using filenames disguised as North Korea to entice recipients to open the files.
Konni Group (also tracked as Opal Sleet , Osmium , TA406 , Vedalia , Earth Imp ) is a North Korea-linked APT group that has been active since at least 2014 , primarily conducting cyberespionage against diplomatic channels, NGOs , academic institutions, government entities, and political organizations in South Korea , Russia , Ukraine , Europe , East Asia , and the Middle East .
See also: LongNosedGoblin hackers use Windows Group Policy for attacks

To protect against such attacks, experts recommend blocking Konni IOCs , disabling PowerShell for non-administrators, enforcing macro blocking in Office , and monitoring KakaoTalk for anomalous outgoing messages. Additionally, educating users about geopolitical baits and using AI detection for obfuscated scripts is critical.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
