Operation Conflict Compass attack chain | Image: SOCRadar Threat Research Unit
At a Glance
| Attribute | Details |
|---|---|
| Actor or Group | Konni (also tracked as TA406 and Opal Sleet; suspected DPRK-nexus group) |
| Activity Type | Spear-phishing, credential theft, host reconnaissance, and remote access |
| Targets or Victims | Foreign policy think tanks, diplomatic entities, and NGOs focused on Ukraine |
| Scale | Targeted intelligence collection across diplomatic and research sectors |
| Jurisdiction / Status | Suspected North Korean state-sponsored threat actors; uncharged |
| Source | SOCRadar Threat Research Unit (STRU) |
Executive Summary
North Korean state-sponsored hackers launched a targeted espionage campaign against organizations studying the war in Ukraine. The attackers used malicious shortcut files disguised as academic documents to deploy a lightweight task runner called VelvetCake. Furthermore, the malware connects to remote servers to download dynamic PowerShell scripts that steal sensitive host data.
What Happened During the Campaign
The attack campaign began in early August 2026 with targeted spear-phishing emails. These emails carried compressed ZIP archives containing shortcut files with Windows LNK extensions. To deceive victims, the threat actors disguised these shortcut files as legitimate PDF documents.
In particular, the attackers crafted lures centered on high-profile geopolitical topics. For example, one lure discussed global food price increases linked to tensions in the Strait of Hormuz. Another lure mimicked a document outlining peace negotiation frameworks between Russia and Ukraine. Additionally, the operators distributed fake resumes of sociological researchers. Consequently, these topics appealed directly to policy analysts and foreign diplomats.
When a victim opens the shortcut, Windows executes a hidden PowerShell command. This command contacts a public GitHub repository to retrieve two malicious scripts. The first script is a VBScript file that establishes persistence on the host. It creates a scheduled task named OneDrive Update Scheduler. This task instructs the operating system to execute a secondary PowerShell downloader every minute.
The downloaded payload is a custom task-queue runner that researchers named VelvetCake. As the primary report highlights, “VelvetCake embeds no fixed post-exploitation capability set locally.” Instead, the malware operates as a lightweight agent that connects to a command server via raw TCP sockets. The implant authenticates using a hardcoded password string. Then, it queries the server for pending execution tasks.
Next, VelvetCake downloads secondary PowerShell scripts and executes them directly in memory. The tool monitors local directories to identify newly created output files. Afterward, it transmits these files back to the server using a custom upload command. The implant then purges the temporary files to hinder forensic analysis. Additionally, researchers observed attackers distributing these same components through trojanized Zoom installers.
Who Is Behind the Intrusions
The SOCRadar Threat Research Unit attributes this activity to the Konni threat group with moderate confidence. Konni operates as a cyberespionage cluster under North Korea’s General Reconnaissance and Information Bureau. Industry researchers also track this suspected threat actor under the aliases TA406 and Opal Sleet.
Historically, Konni functioned as a specialized subgroup within the broader Kimsuky operational umbrella. The group primarily targets foreign policy specialists, diplomatic personnel, and defense researchers. While the threat actors frequently focus on South Korea, they routinely conduct operations across Japan, Europe, and Russia.
Technical evidence strongly supports this attribution assessment. First, the LNK delivery chains and VBScript scheduled tasks match historical Konni intrusion patterns. Second, the Konni Operation Conflict Compass campaign shares command server naming conventions with previous Kimsuky operations. The URLs pass operating system variables and specific keywords such as “cake” to free hosting services.
Furthermore, analysts examined commit timestamps from the attacker’s staging repository on GitHub. The commit history revealed an operational offset matching UTC+9, which corresponds to Korean Standard Time. Specifically, activity concentrated between morning and late afternoon hours with a distinct midday break. This schedule aligns closely with typical state-directed work shifts in the region.
Impact and Operational Scale
The Konni group structured this operation to extract sensitive political and diplomatic intelligence. Specifically, the operators sought insights into the trajectory of the Russia-Ukraine conflict. Because North Korea deployed military personnel to support Russia, Pyongyang needs direct assessments of regional battlefield developments.
To achieve this goal, the secondary reconnaissance scripts collect extensive system information. The script queries local Windows Management Instrumentation to inventory installed antivirus products. In addition, it runs network commands to map system configuration and active network connections.
The malware also enumerates running processes and inspects recently accessed files. Furthermore, the script uses built-in .NET assemblies to capture screenshots of the virtual display. It stages these files in the temporary directory before transmitting them via HTTP POST requests to free web hosts. Because the core implant queries the server every minute, operators can run new reconnaissance modules at will.
How to Stay Protected
Organizations analyzing foreign policy and defense matters face heightened risks from these phishing lures. Therefore, security teams should configure mail gateways to block incoming archive files containing executable shortcuts. Furthermore, administrators should inspect endpoint logs for unauthorized scheduled tasks running from user directories.
Defenders must also monitor network boundaries for abnormal raw TCP socket connections. Legitimate administrative tools rarely communicate over custom high-number network ports without encryption. Additionally, organizations should implement strict application control policies to block unsigned scripts.
Requiring multi-factor authentication and auditing external file-sharing links will help protect sensitive research environments. Finally, regular user awareness training ensures staff members recognize deceptive file extensions before opening suspicious attachments.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!