Description
KONNI is a remote access tool that researchers assess North Korean cyber actors have used since at least 2014. It has significant code overlap with the NOKKI malware family, and researchers have linked it to campaigns targeting political organizations in Russia, East Asia, Europe, and the Middle East, with some evidence potentially connecting it to APT37.
Stats
- First seen
- May 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
40 techniques across 11 tactics.
TA0002 Execution
TA0003 Persistence
TA0004 Privilege Escalation
TA0005 Stealth
TA0007 Discovery
TA0009 Collection
TA0011 Command and Control
TA0010 Exfiltration
TA0112 Defense Impairment
- T1112Modify Registry
Alert name variants
| Alert Name |
|---|
| Script-PowerShell.Trojan.Konni |
| Script-WScript.Trojan.Konni |
| Shortcut.Trojan.Konni |
| Win32.Trojan.Konni |
| Win64.Trojan.Konni |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC Konni.C2 traffic detected |