Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » North Korean Konni Hackers Deploy AI-Based PowerShell Malware

North Korean Konni Hackers Deploy AI-Based PowerShell Malware

North Korean Threat Actor Expands Tactics

Kelly Cromley by Kelly Cromley
Jan 25, 2026
in Market News, News
Reading Time: 3 mins read
0
North Korea

Cybersecurity researchers have reported that the North Korean-linked hacking group known as Konni, also tracked as Opal Sleet or TA406, has begun deploying malware that shows signs of being developed with the assistance of artificial intelligence. The campaign has been observed targeting developers and engineers working in the blockchain and cryptocurrency sector, signaling a continued focus on high-value digital assets and infrastructure.

Konni is widely believed to be connected to other North Korean activity clusters such as APT37 and Kimsuky. The group has been active for more than a decade and has previously focused its operations on organizations across South Korea, Russia, Ukraine, and multiple European countries. Recent findings indicate that its operational scope now places particular emphasis on the Asia-Pacific region.

Asia-Pacific Focus and Initial Infection Vector

Analysis conducted by Check Point researchers revealed that samples linked to the latest campaign were submitted from countries including Japan, Australia, and India. This geographic spread suggests a deliberate effort to compromise targets within the broader Asia-Pacific technology ecosystem.

The infection chain begins with a social engineering approach. Victims receive a link hosted on Discord that leads to the download of a ZIP archive. This archive contains a decoy PDF file alongside a malicious shortcut file in LNK format. When the shortcut is opened, it triggers an embedded PowerShell loader that extracts additional components onto the system.

These components include a DOCX document used as a lure, a cabinet archive, and multiple malicious elements such as a PowerShell backdoor, two batch scripts, and an executable designed to bypass User Account Control protections.

Compromising Development Environments

Opening the shortcut file results in the DOCX document being displayed to the user while, in the background, one of the batch files is executed. According to researchers, the content of the lure document points to a strategic goal of infiltrating development environments. Gaining access at this level could allow attackers to reach critical assets such as infrastructure configurations, application programming interface credentials, digital wallets, and ultimately cryptocurrency funds.

One of the batch scripts creates a staging directory for the backdoor and associated files, while the second establishes a scheduled task that runs hourly. This task is disguised as a legitimate OneDrive startup process, helping it blend into normal system activity.

Obfuscation and AI-Assisted Code Indicators

The scheduled task reads an encrypted PowerShell script from disk, decrypts it using an XOR routine, and executes it directly in memory. After execution, the task removes itself in an effort to erase evidence of compromise. The backdoor code itself is heavily obfuscated through arithmetic-based string encoding, dynamic string reconstruction at runtime, and final execution using PowerShell expression invocation.

Check Point researchers assessed that several characteristics of the script strongly suggested AI-assisted development rather than malware written entirely by a human operator. Indicators included unusually clear and structured documentation within the script, a clean and modular layout, and comments that resembled instructional placeholders commonly seen in large language model outputs and coding tutorials.

Command-and-Control and Attribution

Before fully activating, the malware conducts checks of hardware, software, and user behavior to confirm it is not operating in a sandbox or analysis environment. It then generates a unique identifier for the infected host. Depending on the level of privileges available, the backdoor follows different execution paths.

Once active, the malware periodically communicates with its command-and-control server, transmitting basic system metadata and polling for further instructions at randomized intervals. If the server responds with additional PowerShell code, the backdoor executes it asynchronously using background jobs.

Researchers attributed the campaign to Konni based on similarities with previous attacks, including overlapping launcher formats, lure file naming patterns, and consistent execution chain structures. To assist defenders, Check Point has released indicators of compromise associated with the campaign to help organizations detect and mitigate potential infections.

Previous Post

Binamarket Launches On-Chain Event-Based Trading Platform

Next Post

MixMax and Writeonix Join Forces to Simplify DeFi Access

Related Posts

synbo protocol

Synbo and DeBox Join Forces to Expand Web3 Access

by Kelly Cromley
Apr 30, 2026
0

Synbo Protocol, a decentralized capital and DeFi launchpad platform, announced a strategic partnership with DeBox Social as part of its...

Visa

Visa Expands Stablecoin Settlement Across Nine Blockchains

by Kelly Cromley
Apr 29, 2026
0

Visa is significantly expanding its global stablecoin settlement pilot by adding five new blockchain networks, bringing the total number of...

x1 ecochain

X1 EcoChain and Arkada Build Web3 Reputation Layer

by Kelly Cromley
Apr 29, 2026
0

The Web3 sector is gradually moving away from anonymous speculative activity toward systems that emphasize verified participation and measurable contributions....

POSCO International

Hana, Dunamu, POSCO Build Blockchain Remittance Network

by Kelly Cromley
Apr 29, 2026
0

Hana Financial Group, Dunamu, and POSCO International have entered into a strategic partnership aimed at developing a blockchain-powered overseas remittance...

Chiliz

Chiliz Expands to Base Ahead of Global Sports Surge

by Kelly Cromley
Apr 29, 2026
0

Chiliz has announced a new integration with the Base blockchain network, expanding access to fan token trading and engagement for...

blonex

Blonex Expands Web3 Trading With AI and Token Utility

by Kelly Cromley
Apr 29, 2026
0

As the digital asset industry continues evolving, cryptocurrency trading platforms are facing increasing pressure to deliver more advanced features beyond...

Next Post
mixmax

MixMax and Writeonix Join Forces to Simplify DeFi Access

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

synbo protocol
Market News

Synbo and DeBox Join Forces to Expand Web3 Access

by Kelly Cromley
Apr 30, 2026
Visa
Market News

Visa Expands Stablecoin Settlement Across Nine Blockchains

by Kelly Cromley
Apr 29, 2026
x1 ecochain
Market News

X1 EcoChain and Arkada Build Web3 Reputation Layer

by Kelly Cromley
Apr 29, 2026
POSCO International
Market News

Hana, Dunamu, POSCO Build Blockchain Remittance Network

by Kelly Cromley
Apr 29, 2026
Chiliz
Market News

Chiliz Expands to Base Ahead of Global Sports Surge

by Kelly Cromley
Apr 29, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.