Konni Malware Targets Ukraine Organizations with Fake PDF Files
Key Takeaways A new campaign, dubbed “Operation Conflict Compass,” is targeting individuals and organizations focused on Ukraine. The campaign utilizes deceptive Windows shortcut files...
Key Takeaways
- A new campaign, dubbed “Operation Conflict Compass,” is targeting individuals and organizations focused on Ukraine.
- The campaign utilizes deceptive Windows shortcut files (.LNK) disguised as PDF documents or modified video meeting installers to deliver the VelvetCake malware downloader.
- Researchers from SOCRadar attribute this activity with moderate confidence to Konni, an espionage group linked to North Korea, known for its focus on Ukrainian government entities.
- VelvetCake is designed to establish persistent access, gather system information, capture screenshots, and exfiltrate data, serving the likely purpose of political and military intelligence collection.
A recently uncovered cyber campaign, designated “Operation Conflict Compass,” is actively targeting individuals and organizations engaged with Ukrainian affairs. This operation leverages Windows shortcut files, meticulously crafted to appear as legitimate PDF documents, to deploy a sophisticated malware downloader known as VelvetCake.
Table Of Content
The primary objective of these attacks appears to be the acquisition of sensitive political and military intelligence pertaining to the ongoing conflict in Ukraine. Threat actors are believed to distribute these malicious files via highly targeted email campaigns, embedding them within ZIP archives.
Deceptive Delivery Mechanisms
Upon opening a seemingly innocuous document, such as a peace proposal, an analysis of rising food prices, or even a researcher’s resume, the embedded shortcut file executes malicious code. This process simultaneously displays a decoy document to the unsuspecting user, masking the underlying infection. Another observed attack vector involves a tampered video meeting installer, though the exact distribution method for this variant remains unconfirmed by researchers.
According to SOCRadar said in a report shared with Cyber Security News (CSN), their analysts identified this activity as “Operation Conflict Compass.” They have linked this campaign to Konni, a North Korea-backed espionage group, with moderate confidence. Evidence suggests that the infrastructure supporting this operation has been active since at least August 2026, although the precise number of victims has not yet been verified.
The capabilities of the deployed malware are extensive, enabling the collection of detailed system information, screen captures, and the exfiltration of files from compromised systems. Previous reports concerning attacks by the threat actor TA406 against Ukrainian government entities provide critical context for Konni’s persistent interest in the region. While the current findings confirm a functional surveillance chain, they do not definitively establish confirmed data breaches.
VelvetCake’s Espionage Capabilities
The malicious files are not genuine PDFs, but rather Windows shortcut files (.LNK files) disguised as documents within ZIP archives. The themes of these lures, including “A Century Long Peace Architecture for Ru,” “rising food prices connected to the Strait of Hormuz,” and “CV_OlesiaTsvientukh_SocialResearcher_Sociologist_Qu,” strongly suggest a focus on targets within diplomacy, policy research, and non-governmental organizations, although a definitive victim list has not been released.
Attackers hosted these malicious lures on both a South Korean hosting service and a Ukrainian apparel website. When a target activates the shortcut, it initiates a PowerShell script to download additional components and present the decoy document. This technique mirrors earlier Konni campaigns observed in South Korea, which also utilized disguised shortcuts.
In this campaign, the shortcut executes a script that establishes a scheduled task, ensuring the VelvetCake downloader runs repeatedly. Researchers also identified a modified meeting installer, bundling a legitimate installer with malicious components. While the exact delivery method for this installer is unconfirmed, a meeting invitation is presumed to have prompted its download.
An alternative executable variant identified by researchers loads its code directly from a remote server, bypassing the need to store the main downloader on the compromised disk, thereby enhancing its stealth. This flexible design allows the operators to dynamically alter the malware’s functionality without requiring a complete re-infection.
The scheduled task, set to execute PowerShell every minute, transforms brief bursts of initial activity into a persistent channel for remote command and control. This infection chain bears a resemblance to Kimsuky attacks, where an apparently harmless document serves as the initial entry point for a more extensive compromise.
One follow-on script recovered by investigators performed a comprehensive reconnaissance of the infected system. It enumerated installed security software, system configurations, network settings, active processes, recently accessed files, and available drives. Furthermore, it captured a screenshot and transmitted all collected data to an external server before meticulously deleting its local traces. These findings underscore the campaign’s robust intelligence gathering capabilities, though they do not conclusively prove data theft for every targeted entity.
The attribution of this campaign to Konni is based on several factors, including the Ukraine-centric themes, the use of shortcut-based delivery, shared infrastructure, and observed operator tactics. However, researchers emphasize that attribution is not definitive, as factors like a repository’s time-zone setting, while supportive, cannot solely determine an operator’s physical location. The report consistently describes activities aligned with intelligence collection, refraining from explicitly naming affected organizations.
What You Should Do
- Organizations involved in sensitive work related to Ukraine must exercise extreme caution with unexpected document attachments and meeting installers.
- Always verify the true file type of attachments before opening them, regardless of the displayed icon or extension.
- Actively monitor for unusual scheduled tasks created on endpoints.
- Regularly review PowerShell activity logs for suspicious commands or scripts.
- Implement robust email security solutions capable of detecting malicious attachments and links.
- Educate employees on phishing awareness, specifically highlighting the tactics used in this campaign, such as disguised shortcut files.
Indicators of Compromise (IoCs):-



No Comment! Be the first one.