Opal Sleet

Aliases: OSMIUM, Konni, Vedalia, VELVET CHOLLIMA, Planedown, APT43

First seen
2012-01-01 00:00:00
Origin
KP
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-20 00:40:38
Profile updated
2026-07-07 12:08:41

Targeted industries: education-and-nonprofits government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:kr country_code:jp country_code:us country_code:vn

Context

Konni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activities. Konni has targeted various sectors, including education, government, business organizations, and the cryptocurrency industry. They have exploited vulnerabilities such as CVE-2023-38831 and have used malware like KonniRAT to gain control of victim hosts and steal important information.

Exploited vulnerabilities

  • CVE-2023-38831 (vulnerability)

Related threat objects

Reports & references

  • nsfocusglobal.com — The New Apt Group Darkcasino And The Global Surge In Winrar 0 Day Exploits (report)
  • paper.seebug.org — 3031 (report)
  • rewterz.com — Rewterz Threat Alert Konni Apt Group Active Iocs 11 (report)
  • securonix.com — Stiffbizon Detection New Attack Campaign Observed (report)
  • gbhackers.com — Vedalia Apt Group Exploits (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references