Opal Sleet
Aliases: OSMIUM, Konni, Vedalia, VELVET CHOLLIMA, Planedown, APT43
- First seen
- 2012-01-01 00:00:00
- Origin
- KP
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-20 00:40:38
- Profile updated
- 2026-07-07 12:08:41
Targeted industries: education-and-nonprofits government-and-public-sector financial-services technology-and-telecommunications
Targeted regions: country_code:kr country_code:jp country_code:us country_code:vn
Context
Konni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activities. Konni has targeted various sectors, including education, government, business organizations, and the cryptocurrency industry. They have exploited vulnerabilities such as CVE-2023-38831 and have used malware like KonniRAT to gain control of victim hosts and steal important information.
Exploited vulnerabilities
- CVE-2023-38831 (vulnerability)
Related threat objects
- Kimsuky (threat-actor)
Reports & references
- nsfocusglobal.com — The New Apt Group Darkcasino And The Global Surge In Winrar 0 Day Exploits (report)
- paper.seebug.org — 3031 (report)
- rewterz.com — Rewterz Threat Alert Konni Apt Group Active Iocs 11 (report)
- securonix.com — Stiffbizon Detection New Attack Campaign Observed (report)
- gbhackers.com — Vedalia Apt Group Exploits (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)