KONNI

MITRE ATT&CK: S0356 View on attack.mitre.org

Aliases: KONNI

First seen
2014-01-01 00:00:00
Malware type
rat
Family
Malware family
Operating systems
windows
Related IoCs
91 (79 malicious)
Last IoC activity
2026-09-02 00:38:08
Profile updated
2026-07-07 12:52:41

Targeted industries: government-and-public-sector

Targeted regions: country_code:ru country_code:kr country_code:jp

Context

KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014. KONNI has significant code overlap with the NOKKI malware family, and has been linked to several suspected North Korean campaigns targeting political organizations in Russia, East Asia, Europe and the Middle East; there is some evidence potentially linking KONNI to APT37.

Recent IoC activity

79 malicious indicators in Maltiverse are attributed to KONNI (S0356). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname playdxb.com 2026-09-03 1
hostname xcellentrenovations.com 2026-09-03 1
hostname nationalinterestparty.com 2026-09-02 1
hostname serviceset.net 2026-09-02 1
hostname oldfoxcompany.com 2026-09-02 1
hostname priesttools.com 2026-09-02 1
hostname nailemkosmetik.de 2026-09-02 1
hostname meditationsecretsforwomen.com 2026-09-02 1
hostname sarahmariegerrity.com 2026-09-02 1
hostname techtorev.com 2026-09-02 1
hostname gg1593.c1.biz 2026-09-02 1
hostname roofcolor.com 2026-09-02 1
hostname notkittenaround.digmoo.com 2026-08-28 1
hostname ttzcloud.com 2026-08-27 1
file sample SpravkiBKsetup_ver._2.5.msi 2026-08-21 1
file sample 174f1e0c65001b227383b46568b084cdf4fc450485c7363a7ff77bf1ee218652 2026-08-17 3
URL http://centhosting.net/upload.php 2026-08-01 1
hostname centhosting.net 2026-08-01 1
URL http://serviceset.net/upload.php 2026-08-01 1
file sample install.cab 2026-08-01 1

Detection coverage

  • 8 YARA rules
  • 836 Sigma rules

Malware & tools used

  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Malicious File (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Component Object Model Hijacking (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Credentials from Web Browsers (attack-pattern)
  • Data from Local System (attack-pattern)
  • Parent PID Spoofing (attack-pattern)
  • Software Packing (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Clipboard Data (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Process Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • Modify Registry (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Detection rules

  • DITEKSHEN_MALWARE_Win_Konni (yara-rule)
  • SEKOIA_Kimsuky_Konni_Dll (yara-rule)
  • SEKOIA_Apt_Konni_Check_Bat (yara-rule)
  • SEKOIA_Apt_Konni (yara-rule)
  • SEKOIA_Loader_Win_Konni_Bat (yara-rule)
  • SEKOIA_Apt_Konni_Dropper (yara-rule)
  • SEKOIA_Rat_Win_Konni_Rat (yara-rule)
  • SEKOIA_Dropper_Win_Konni_Cab (yara-rule)

Related threat objects

Reports & references

  • bleepingcomputer.com — Report Ties North Korean Attacks To New Malware Linked By Word Macros (report)
  • Cisco Talos — Konni References North Korean Missile Capabilities (report)
  • medium.com — A Look Into Konni 2019 Campaign B45A0F321E9B (report)
  • blog.malwarebytes.com — New Variant Of Konni Malware Used In Campaign Targetting Russia (report)
  • blog.fortinet.com — A Quick Look At A New Konni Rat Variant (report)
  • vallejo.cc — Analysis Of New Variant Of Konni Rat (report)
  • researchcenter.paloaltonetworks.com — Unit42 Nokki Almost Ties The Knot With Dogcall Reaper Group Uses New Malware To Deploy Rat (report)
  • researchcenter.paloaltonetworks.com — Unit42 New Konni Malware Attacking Eurasia Southeast Asia (report)
  • MITRE ATT&CK — S0356 (report)
  • Cisco Talos — Konni Malware Under Radar For Years (report)
  • cylance.com — Threat Spotlight Konni Stealthy Remote Access Trojan (report)

External references