North Korean Hackers Target Ukraine-Related Intelligence with Fake Documents
SOCRadar's Threat Research Unit has identified a new campaign, dubbed Operation Conflict Compass, run by the North Korea-aligned threat actor Konni. The campaign appears aimed at gathering intelligence on the trajectory of the Russia-Ukraine war, with lures referencing global food price rises, peace negotiation frameworks, and fake social researcher resumes.
The attackers likely gain initial access through spear-phishing emails carrying ZIP attachments. Inside are LNK files disguised as PDF documents. When opened, these files deploy a newly identified malware strain named VelvetCake. Rather than carrying fixed capabilities, VelvetCake acts as a lightweight task runner that continuously fetches and runs PowerShell modules from a remote server, letting attackers change its functions without needing to redeploy the malware itself.
Konni, also known as TA406 or Opal Sleet, has operated since at least 2014 under North Korea's military intelligence apparatus and is considered a subgroup of the larger Kimsuky network. While its main focus has been South Korea, the group regularly expands operations to Japan, Russia, and European targets involved in foreign policy and defence. Its signature approach relies on spear-phishing with malicious LNK files leading to PowerShell-based loaders and remote access trojans.