Analysis of the Spear-Phishing and KakaoTalk-Linked Threat Campaign

The Konni Group conducted a sophisticated multi-stage attack campaign, initiating with a spear-phishing email disguised as a North Korean human rights lecturer appointment. The attack progressed through execution of a malicious LNK file, installation of remote access malware, and long-term persistence for data theft. A key feature was the unauthorized access to victims' KakaoTalk PC applications, used to distribute additional malicious files to selected contacts. The campaign employed multiple RAT families, including EndRAT, RftRAT, and RemcosRAT, with a distributed C2 infrastructure across Finland, Japan, and the Netherlands. The threat actor's tactics included trust-based propagation, account session abuse, and modular payload deployment, highlighting the need for advanced behavior-based detection and multi-layered defense strategies.

Pulse ID: 69ba831f2287b29db4e4645e
Pulse Link: https://otx.alienvault.com/pulse/69ba831f2287b29db4e4645e
Pulse Author: AlienVault
Created: 2026-03-18 10:49:03

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #DRat #DataTheft #Email #Finland #ICS #InfoSec #Japan #Konni #Korea #LNK #Malware #NorthKorea #OTX #OpenThreatExchange #Phishing #RAT #Remcos #RemcosRAT #Rust #SpearPhishing #TheNetherlands #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Also, #survHEhmc (to run Bayesian modelling for survival analysis in HTA using HMC/pre-compiled @mcmc_stan models) and #survHMCinla (to run some Bayesian models for survival analysis in HTA using INLA) are now updated on GitHub and available via #drat repo)

https://github.com/giabaio/survHEhmc

https://github.com/giabaio/survHEinla

GitHub - giabaio/survHEhmc: Survival analysis in health economic evaluation using Bayesian modelling and Hamiltonian Monte Carlo Contains a suite of functions to systematise the workflow involving survival analysis in health economic evaluation.

Survival analysis in health economic evaluation using Bayesian modelling and Hamiltonian Monte Carlo Contains a suite of functions to systematise the workflow involving survival analysis in health ...

GitHub

Oh #drat, there's already such a thing as a "St. Clement's cake" – I thought I'd cleverly invented the name by noting the nursery rhyme reference… I suppose it was an obvious observation.

I just duck-searched it on a whim to find documented recipes all over the place. lol

Interestingly this example has almond involved too, so my addition of marzipan isn't even inventive.

Someone once said "there's nothing new in the kitchen," and I suspect that's probably right.

https://thehappyfoodie.co.uk/recipes/st-clements-cake/

St Clement's Cake

This recipe for St Clement's Cake, from The Lemon Tree Cafe, makes a vibrant cake full of wonderful citrus flavours.

The Happy Foodie
Hmm, two hour delay on receiving AT&T phone messages today. Missed the call from the plumber (didn't ring here, either). #drat