KONNI
MITRE ATT&CK: S0356 View on attack.mitre.org
Aliases: KONNI
- First seen
- 2014-01-01 00:00:00
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 91 (79 malicious)
- Last IoC activity
- 2026-09-02 00:38:08
- Profile updated
- 2026-07-07 12:52:41
Targeted industries: government-and-public-sector
Targeted regions: country_code:ru country_code:kr country_code:jp
Context
KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014. KONNI has significant code overlap with the NOKKI malware family, and has been linked to several suspected North Korean campaigns targeting political organizations in Russia, East Asia, Europe and the Middle East; there is some evidence potentially linking KONNI to APT37.
Recent IoC activity
79 malicious indicators in Maltiverse are attributed to KONNI (S0356). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | playdxb.com | 2026-09-03 | 1 |
| hostname | xcellentrenovations.com | 2026-09-03 | 1 |
| hostname | nationalinterestparty.com | 2026-09-02 | 1 |
| hostname | serviceset.net | 2026-09-02 | 1 |
| hostname | oldfoxcompany.com | 2026-09-02 | 1 |
| hostname | priesttools.com | 2026-09-02 | 1 |
| hostname | nailemkosmetik.de | 2026-09-02 | 1 |
| hostname | meditationsecretsforwomen.com | 2026-09-02 | 1 |
| hostname | sarahmariegerrity.com | 2026-09-02 | 1 |
| hostname | techtorev.com | 2026-09-02 | 1 |
| hostname | gg1593.c1.biz | 2026-09-02 | 1 |
| hostname | roofcolor.com | 2026-09-02 | 1 |
| hostname | notkittenaround.digmoo.com | 2026-08-28 | 1 |
| hostname | ttzcloud.com | 2026-08-27 | 1 |
| file sample | SpravkiBKsetup_ver._2.5.msi | 2026-08-21 | 1 |
| file sample | 174f1e0c65001b227383b46568b084cdf4fc450485c7363a7ff77bf1ee218652 | 2026-08-17 | 3 |
| URL | http://centhosting.net/upload.php | 2026-08-01 | 1 |
| hostname | centhosting.net | 2026-08-01 | 1 |
| URL | http://serviceset.net/upload.php | 2026-08-01 | 1 |
| file sample | install.cab | 2026-08-01 | 1 |
Detection coverage
- 8 YARA rules
- 836 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Malicious File (attack-pattern)
- System Information Discovery (attack-pattern)
- Component Object Model Hijacking (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Credentials from Web Browsers (attack-pattern)
- Data from Local System (attack-pattern)
- Parent PID Spoofing (attack-pattern)
- Software Packing (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Web Protocols (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Clipboard Data (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Process Discovery (attack-pattern)
- PowerShell (attack-pattern)
- Modify Registry (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Archive Collected Data (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Detection rules
- DITEKSHEN_MALWARE_Win_Konni (yara-rule)
- SEKOIA_Kimsuky_Konni_Dll (yara-rule)
- SEKOIA_Apt_Konni_Check_Bat (yara-rule)
- SEKOIA_Apt_Konni (yara-rule)
- SEKOIA_Loader_Win_Konni_Bat (yara-rule)
- SEKOIA_Apt_Konni_Dropper (yara-rule)
- SEKOIA_Rat_Win_Konni_Rat (yara-rule)
- SEKOIA_Dropper_Win_Konni_Cab (yara-rule)
Related threat objects
- Konni (Windows) (malware)
Reports & references
- bleepingcomputer.com — Report Ties North Korean Attacks To New Malware Linked By Word Macros (report)
- Cisco Talos — Konni References North Korean Missile Capabilities (report)
- medium.com — A Look Into Konni 2019 Campaign B45A0F321E9B (report)
- blog.malwarebytes.com — New Variant Of Konni Malware Used In Campaign Targetting Russia (report)
- blog.fortinet.com — A Quick Look At A New Konni Rat Variant (report)
- vallejo.cc — Analysis Of New Variant Of Konni Rat (report)
- researchcenter.paloaltonetworks.com — Unit42 Nokki Almost Ties The Knot With Dogcall Reaper Group Uses New Malware To Deploy Rat (report)
- researchcenter.paloaltonetworks.com — Unit42 New Konni Malware Attacking Eurasia Southeast Asia (report)
- MITRE ATT&CK — S0356 (report)
- Cisco Talos — Konni Malware Under Radar For Years (report)
- cylance.com — Threat Spotlight Konni Stealthy Remote Access Trojan (report)