Konni (Windows)

First seen
2014-01-01 00:00:00
Malware type
rat
Family
Malware family
Profile updated
2026-07-07 12:52:45

Targeted industries: government-and-public-sector

Targeted regions: country_code:kr country_code:jp country_code:vn country_code:ru country_code:np country_code:cn country_code:in country_code:ro country_code:kw

Context

Konni is a remote administration tool, observed in the wild since early 2014. The Konni malware family is potentially linked to APT37, a North-Korean cyber espionage group active since 2012. The group primary victims are South-Korean political organizations, as well as Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East.

Related threat objects

Reports & references

  • Kaspersky — 90729 (report)
  • nsfocusglobal.com — The New Apt Group Darkcasino And The Global Surge In Winrar 0 Day Exploits (report)
  • securonix.com — Stiffbizon Detection New Attack Campaign Observed (report)
  • cocomelonc.github.io — Malware Pers 3 (report)
  • cocomelonc.github.io — Malware Tricks 23 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Konni (report)
  • wezard4u.tistory.com — 6693 (report)
  • CISA — Aa20 227A (report)
  • Cisco Talos — Konni References North Korean Missile Capabilities (report)
  • medium.com — A Look Into Konni 2019 Campaign B45A0F321E9B (report)
  • threatmon.io — The Konni Apt Chronicle Tracing Their Intelligence Driven Attack Chain (report)
  • blog.malwarebytes.com — Konni Evolves Into Stealthier Rat (report)
  • blog.malwarebytes.com — New Variant Of Konni Malware Used In Campaign Targetting Russia (report)
  • bleepingcomputer.com — Hackers Take Over Diplomats Email Target Russian Deputy Minister (report)
  • medium.com — To Russia With Love Assessing A Konni Backdoored Suspected Russian Consular Software Installer Ce618Ea4B8F3 (report)
  • cluster25.io — Konni Targeting Russian Diplomatic Sector (report)
  • blog.fortinet.com — A Quick Look At A New Konni Rat Variant (report)
  • e.cyberint.com — Cyberint Konni%20Malware%202019%20Campaign Report (report)
  • bleepingcomputer.com — North Korean Hackers Attack Eu Targets With Konni Rat Malware (report)
  • blog.lumen.com — New Konni Campaign Targeting Russian Ministry Of Foreign Affairs (report)
  • vallejo.cc — Analysis Of New Variant Of Konni Rat (report)
  • Cisco Talos — Konni Malware Under Radar For Years (report)
  • blog.alyac.co.kr — 2474 (report)

External references