Advertise
CoinTrust
BTC
ETH
BCH
SOL
DOGE
SHIB
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos
No Result
View All Result
CoinTrust
No Result
View All Result

Home » North Korean Konni Hackers Deploy AI-Based PowerShell Malware

North Korean Konni Hackers Deploy AI-Based PowerShell Malware

North Korean Threat Actor Expands Tactics

Kelly Cromley by Kelly Cromley
Jan 25, 2026
in Market News, News
Reading Time: 3 mins read
0
North Korea

Cybersecurity researchers have reported that the North Korean-linked hacking group known as Konni, also tracked as Opal Sleet or TA406, has begun deploying malware that shows signs of being developed with the assistance of artificial intelligence. The campaign has been observed targeting developers and engineers working in the blockchain and cryptocurrency sector, signaling a continued focus on high-value digital assets and infrastructure.

Konni is widely believed to be connected to other North Korean activity clusters such as APT37 and Kimsuky. The group has been active for more than a decade and has previously focused its operations on organizations across South Korea, Russia, Ukraine, and multiple European countries. Recent findings indicate that its operational scope now places particular emphasis on the Asia-Pacific region.

Asia-Pacific Focus and Initial Infection Vector

Analysis conducted by Check Point researchers revealed that samples linked to the latest campaign were submitted from countries including Japan, Australia, and India. This geographic spread suggests a deliberate effort to compromise targets within the broader Asia-Pacific technology ecosystem.

The infection chain begins with a social engineering approach. Victims receive a link hosted on Discord that leads to the download of a ZIP archive. This archive contains a decoy PDF file alongside a malicious shortcut file in LNK format. When the shortcut is opened, it triggers an embedded PowerShell loader that extracts additional components onto the system.

These components include a DOCX document used as a lure, a cabinet archive, and multiple malicious elements such as a PowerShell backdoor, two batch scripts, and an executable designed to bypass User Account Control protections.

north korea-1

 

Compromising Development Environments

Opening the shortcut file results in the DOCX document being displayed to the user while, in the background, one of the batch files is executed. According to researchers, the content of the lure document points to a strategic goal of infiltrating development environments. Gaining access at this level could allow attackers to reach critical assets such as infrastructure configurations, application programming interface credentials, digital wallets, and ultimately cryptocurrency funds.

north korea-2

One of the batch scripts creates a staging directory for the backdoor and associated files, while the second establishes a scheduled task that runs hourly. This task is disguised as a legitimate OneDrive startup process, helping it blend into normal system activity.

Obfuscation and AI-Assisted Code Indicators

The scheduled task reads an encrypted PowerShell script from disk, decrypts it using an XOR routine, and executes it directly in memory. After execution, the task removes itself in an effort to erase evidence of compromise. The backdoor code itself is heavily obfuscated through arithmetic-based string encoding, dynamic string reconstruction at runtime, and final execution using PowerShell expression invocation.

north korea-3

Check Point researchers assessed that several characteristics of the script strongly suggested AI-assisted development rather than malware written entirely by a human operator. Indicators included unusually clear and structured documentation within the script, a clean and modular layout, and comments that resembled instructional placeholders commonly seen in large language model outputs and coding tutorials.

north korea-4

 

 

Command-and-Control and Attribution

Before fully activating, the malware conducts checks of hardware, software, and user behavior to confirm it is not operating in a sandbox or analysis environment. It then generates a unique identifier for the infected host. Depending on the level of privileges available, the backdoor follows different execution paths.

Once active, the malware periodically communicates with its command-and-control server, transmitting basic system metadata and polling for further instructions at randomized intervals. If the server responds with additional PowerShell code, the backdoor executes it asynchronously using background jobs.

Researchers attributed the campaign to Konni based on similarities with previous attacks, including overlapping launcher formats, lure file naming patterns, and consistent execution chain structures. To assist defenders, Check Point has released indicators of compromise associated with the campaign to help organizations detect and mitigate potential infections.

Previous Post

Binamarket Launches On-Chain Event-Based Trading Platform

Related Posts

binamarket

Binamarket Launches On-Chain Event-Based Trading Platform

by Kelly Cromley
Jan 25, 2026
0

Binamarket, a decentralized on-chain marketplace, has unveiled its event-based trading infrastructure designed to support markets linked to publicly verifiable real-world...

Visa

Visa and Mercuryo Bring Crypto Closer to Everyday Payments

by Kelly Cromley
Jan 25, 2026
0

A new partnership between Visa and Mercuryo is set to reshape how digital assets are used for daily transactions. The...

cache wallet

Cache Wallet and MeloBoom Join Forces to Simplify Web3 Access

by Kelly Cromley
Jan 25, 2026
0

Cache Wallet, a widely recognized multi-chain cryptocurrency wallet provider, has entered into a strategic partnership with MeloBoom, a Web3 organization...

plasma

Plasma Integrates NEAR Intents to Streamline Stablecoin Swaps

by Kelly Cromley
Jan 24, 2026
0

Plasma, a recently launched Layer-1 blockchain network focused on improving the speed, cost efficiency, and reliability of global stablecoin payments,...

Saga

SagaEVM Halts Operations After $7M Exploit Investigation

by Kelly Cromley
Jan 24, 2026
0

Operations on the SagaEVM blockchain have been temporarily suspended after a security incident resulted in the loss of nearly $7...

spacecoin partners with world liberty financial

Spacecoin and WLFI Advance Satellite-Powered DeFi Infrastructure

by Kelly Cromley
Jan 24, 2026
0

Spacecoin and World Liberty Financial have disclosed a strategic partnership aimed at building a satellite-powered decentralized finance and internet ecosystem...

  • Collé Ai

    Collé: Pioneering AI Web3 Platform Receives Investment Boost from BlackRock

    by Kelly Cromley
    May 13, 2024
  • Router Protocol and OpenWorldSwap Partnership to Revolutionize DEX Market

    by Kelly Cromley
    Aug 6, 2024
  • Hyper Foundation Launched to Boost Hyperliquid Blockchain Development

    by Kelly Cromley
    Oct 15, 2024
  • SmarTrust Brings Blockchain-Powered Escrow to Freelancers

    by Kelly Cromley
    May 1, 2025
  • Blockchain Based Sports Platform SportsMint Unveiled

    by Kelly Cromley
    Apr 30, 2024

Recent News

North Korea
Market News

North Korean Konni Hackers Deploy AI-Based PowerShell Malware

by Kelly Cromley
Jan 25, 2026
binamarket
Market News

Binamarket Launches On-Chain Event-Based Trading Platform

by Kelly Cromley
Jan 25, 2026
Visa
Market News

Visa and Mercuryo Bring Crypto Closer to Everyday Payments

by Kelly Cromley
Jan 25, 2026
cache wallet
Market News

Cache Wallet and MeloBoom Join Forces to Simplify Web3 Access

by Kelly Cromley
Jan 25, 2026
plasma
Market News

Plasma Integrates NEAR Intents to Streamline Stablecoin Swaps

by Kelly Cromley
Jan 24, 2026

Categories

  • Altcoin News
  • Analysis News
  • Binance Coin News
  • Bitcoin News
  • Blog
  • Cardano News
  • Ethereum News
  • ICO News
  • Legislation News
  • Market Forecasts
  • Market News
  • News
  • Ripple News
  • Solana News
  • Tether News
  • XRP
Trustpilot

Cointrust

  • About Us
  • Contact Us
  • Correction Request
  • Our Team

Legal

  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy

Popular

  • ICO Listings
  • Knowledge Base
  • All about Mining
  • Cryptocurrency Exchanges
  • How and Where to buy Cryptocurrency

Sitemap

  • News section
  • Sitemap
  • XML Sitemap

© 2024 CoinTrust.com.

CoinTrustCoinTrust

* DISCLAIMER: All information provided in CoinTrust is merely for informational purposes, we are not an investment advisor and not affiliated with any companies or ICO/Cryptocurrency Projects. To use this website you must accept our cookie policy, Disclaimer and Privacy Policies.

No Result
View All Result
  • News
  • Bitcoin
  • Ethereum
  • Altcoin
  • Market Cap
  • Learn
    • Buying Crypto
    • Crypto Mining
    • Crypto Exchanges
    • Knowledge
  • Crypto Casinos
    • Bitcoin Casinos
    • New Crypto Casinos
    • No KYC Crypto Casinos
    • Anonymous Crypto Casinos
    • VPN Friendly Crypto Casinos
    • Bitcoin Poker
    • Crypto Poker
    • Bitcoin Bingo
    • USDT Casinos
    • Offshore Online Casinos
    • Bitcoin Betting Sites
    • Crypto Sports Betting
    • Reddit’s Best Bitcoin and Crypto Casinos

© 2024 CoinTrust.com.

We use cookies to ensure that we give you the best experience on our website.
If you continue to use this site you agree to allow us to use cookies, in accordance with our Cookie Policy.