Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
AvisLoader Malware Adapts to Survive Server Takedowns
September 24, 2026
Konni Malware Targets Ukraine Organizations with Fake PDF Files
September 24, 2026
New Android Banking Trojan Steals PINs with AI-Generated Overlays
September 24, 2026
Home/Threats/Konni Malware Targets Ukraine Organizations with Fake PDF Files
Threats

Konni Malware Targets Ukraine Organizations with Fake PDF Files

Key Takeaways A new campaign, dubbed “Operation Conflict Compass,” is targeting individuals and organizations focused on Ukraine. The campaign utilizes deceptive Windows shortcut files...

Emy Elsamnoudy
Emy Elsamnoudy
September 24, 2026 4 Min Read
2 0

Key Takeaways

  • A new campaign, dubbed “Operation Conflict Compass,” is targeting individuals and organizations focused on Ukraine.
  • The campaign utilizes deceptive Windows shortcut files (.LNK) disguised as PDF documents or modified video meeting installers to deliver the VelvetCake malware downloader.
  • Researchers from SOCRadar attribute this activity with moderate confidence to Konni, an espionage group linked to North Korea, known for its focus on Ukrainian government entities.
  • VelvetCake is designed to establish persistent access, gather system information, capture screenshots, and exfiltrate data, serving the likely purpose of political and military intelligence collection.

A recently uncovered cyber campaign, designated “Operation Conflict Compass,” is actively targeting individuals and organizations engaged with Ukrainian affairs. This operation leverages Windows shortcut files, meticulously crafted to appear as legitimate PDF documents, to deploy a sophisticated malware downloader known as VelvetCake.

Table Of Content

  • Key Takeaways
  • Deceptive Delivery Mechanisms
  • VelvetCake’s Espionage Capabilities
  • What You Should Do

The primary objective of these attacks appears to be the acquisition of sensitive political and military intelligence pertaining to the ongoing conflict in Ukraine. Threat actors are believed to distribute these malicious files via highly targeted email campaigns, embedding them within ZIP archives.

Deceptive Delivery Mechanisms

Upon opening a seemingly innocuous document, such as a peace proposal, an analysis of rising food prices, or even a researcher’s resume, the embedded shortcut file executes malicious code. This process simultaneously displays a decoy document to the unsuspecting user, masking the underlying infection. Another observed attack vector involves a tampered video meeting installer, though the exact distribution method for this variant remains unconfirmed by researchers.

According to SOCRadar said in a report shared with Cyber Security News (CSN), their analysts identified this activity as “Operation Conflict Compass.” They have linked this campaign to Konni, a North Korea-backed espionage group, with moderate confidence. Evidence suggests that the infrastructure supporting this operation has been active since at least August 2026, although the precise number of victims has not yet been verified.

The capabilities of the deployed malware are extensive, enabling the collection of detailed system information, screen captures, and the exfiltration of files from compromised systems. Previous reports concerning attacks by the threat actor TA406 against Ukrainian government entities provide critical context for Konni’s persistent interest in the region. While the current findings confirm a functional surveillance chain, they do not definitively establish confirmed data breaches.

VelvetCake’s Espionage Capabilities

The malicious files are not genuine PDFs, but rather Windows shortcut files (.LNK files) disguised as documents within ZIP archives. The themes of these lures, including “A Century Long Peace Architecture for Ru,” “rising food prices connected to the Strait of Hormuz,” and “CV_OlesiaTsvientukh_SocialResearcher_Sociologist_Qu,” strongly suggest a focus on targets within diplomacy, policy research, and non-governmental organizations, although a definitive victim list has not been released.

Attackers hosted these malicious lures on both a South Korean hosting service and a Ukrainian apparel website. When a target activates the shortcut, it initiates a PowerShell script to download additional components and present the decoy document. This technique mirrors earlier Konni campaigns observed in South Korea, which also utilized disguised shortcuts.

In this campaign, the shortcut executes a script that establishes a scheduled task, ensuring the VelvetCake downloader runs repeatedly. Researchers also identified a modified meeting installer, bundling a legitimate installer with malicious components. While the exact delivery method for this installer is unconfirmed, a meeting invitation is presumed to have prompted its download.

An alternative executable variant identified by researchers loads its code directly from a remote server, bypassing the need to store the main downloader on the compromised disk, thereby enhancing its stealth. This flexible design allows the operators to dynamically alter the malware’s functionality without requiring a complete re-infection.

The scheduled task, set to execute PowerShell every minute, transforms brief bursts of initial activity into a persistent channel for remote command and control. This infection chain bears a resemblance to Kimsuky attacks, where an apparently harmless document serves as the initial entry point for a more extensive compromise.

One follow-on script recovered by investigators performed a comprehensive reconnaissance of the infected system. It enumerated installed security software, system configurations, network settings, active processes, recently accessed files, and available drives. Furthermore, it captured a screenshot and transmitted all collected data to an external server before meticulously deleting its local traces. These findings underscore the campaign’s robust intelligence gathering capabilities, though they do not conclusively prove data theft for every targeted entity.

The attribution of this campaign to Konni is based on several factors, including the Ukraine-centric themes, the use of shortcut-based delivery, shared infrastructure, and observed operator tactics. However, researchers emphasize that attribution is not definitive, as factors like a repository’s time-zone setting, while supportive, cannot solely determine an operator’s physical location. The report consistently describes activities aligned with intelligence collection, refraining from explicitly naming affected organizations.

What You Should Do

  • Organizations involved in sensitive work related to Ukraine must exercise extreme caution with unexpected document attachments and meeting installers.
  • Always verify the true file type of attachments before opening them, regardless of the displayed icon or extension.
  • Actively monitor for unusual scheduled tasks created on endpoints.
  • Regularly review PowerShell activity logs for suspicious commands or scripts.
  • Implement robust email security solutions capable of detecting malicious attachments and links.
  • Educate employees on phishing awareness, specifically highlighting the tactics used in this campaign, such as disguised shortcut files.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/ GitHub account listed in the source’s network indicators.
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/media Source-listed GitHub URL; the PDF may cut off its ending.
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/medianews Source-listed GitHub URL; the PDF may cut off its ending.<a rel="noopener" target="_blank" href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/3ece8449-30db-47a5-a367-e7c600f9e58e/Fake-PDF-Files-Hide-Konni-Malware-Campaign-Targeting-Ukraine-Organizations.pdf?AWSAccessKeyId=ASIA2F3EMEYE2NWJDVEN&Signature=P2QvZIoTbhFTSFFJWq%2BxMULAAX4%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEA0aCXVzLWVhc3QtMSJHMEUCIQC%2Felt4ByU%2BLaOjMkSMQuLln4YGTCgFRBOk%2FBEhg1Fi3QIgF5l1HO%2B%2FFQZAfk6gwYC%2Fubg%2FN1ODXqXazKZlcK7choUq%2FAQI1f%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARABGgw2OTk3NTMzMDk3MDUiDH1%2FafqT5eEgC1ymRSrQBECBgEE%2FvRcxmHEXFavOcDVvXcIwceYhPa2FNhWD23cg90u5FqOCsxdDI9%2FvNr3ojtONe%2FbwEm0f3oAT7wAbHdLFNA0tfzIfmZN9nPNosut%2FT%2BSTbv9A6fMgMuKLfjHWmbBXXUlxQ6Y90qXlWfKECwyw4UaRrab5FEn2LPCAX9pQXie7%2FJCF9caViMQGeGpDPcoNa76WhFOZFYwIfIzMEDi6v9EIExvDaQr0TnNPIddyL6%2FFHqWmEcq%2B0wEqqFb2KgBp6hCvb9We5wZx21sx8yTs3H0cS1%2FDP03czEdJSlyqXtksyyg0x4YrBcrDSPj%2BKvovoeic%2BbNElYHSAHnJjF978bZM8i7OF0p0wOlRUQK8UAtdWK55QxEUu%2Bm%2FDHHYBOM%2FVoGT%2FxouChC%2FHF9Uq31%2BBP40ZuX6ph2aWoohhCnpfsaDvbNkpycWYSLIUo6BidYYiEEO0ZKF7tYnKgazvejiDvK2wUXLYRaWgajzzhj8N4D9FmSfQo4giz2uh34M9ERHflVgu3cSs5pxlfjGuf0K595FQYXU4w9vOA2Endi3XyLXY%2F8yjb%2BVKEyK157KnR%2B1vDpklXXPE7vxfezXY8YATPCm2zdAWBtubCj0smgjLMtxn3k%2B58TNrxlo8Aliyt4DJvzH7Qub%2B32gJXT74AECw6Vt0n6BmsUs1FTriU0KfVV3h4m%2BLaa9KlQIkN%2FNEYIrjYTc7y4sSa6fv7N6G%2FJTaF5NBFHovv4KDV8JRLS7v%2FtYORkCMsmgGK9%2Ft7rk0NI2MnQ04u6I%2Fh1U5KFjFGcw9ajU1QY6mAFr%2F7MGbNTu9KH3IZycwSgZ2FodtXs98BwVB91paEPc3QlzRfy9MSrJtvCXHkEz8hgoqd%2FkL2PdyxEVynk%2BAOo6fG%2BUTu0gAE57dNvI2wFjf3%2FZePOIYqzCj2TYp5ErcYZWYjieXO3K%2

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreat

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

New Android Banking Trojan Steals PINs with AI-Generated Overlays

Next Post

AvisLoader Malware Adapts to Survive Server Takedowns

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Galago Ransomware Emerges, Linked to Panzer Group
September 24, 2026
Critical Check Point VPN Flaws Let Attackers Gain Remote Access Without Login
September 24, 2026
Critical Roundcube SQL Injection CVE-2023-43770 Exploited in Attacks
September 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us