Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations
SOCRadar links Operation Conflict Compass, a Konni espionage campaign using fake PDF shortcuts and the VelvetCake downloader, to Ukraine-focused targeting.
SOCRadar documents Operation Conflict Compass, attributed with moderate confidence to North Korea-linked Konni, targeting diplomacy, policy research, and NGO figures working on Ukraine. Weaponized ZIP archives contain Windows LNK files disguised as peace-proposal and resume PDFs that launch PowerShell, create a scheduled task running every minute, and deploy the VelvetCake downloader. VelvetCake fetches remote scripts, gathers system information, captures screenshots, uploads collected files to attacker infrastructure, and deletes local traces. Infrastructure tied to the operation appeared as early as August 2026, but no verified victim count was published.
- LNK shortcuts disguised as peace-proposal PDFs launch PowerShell and decoy documents
- VelvetCake downloader runs remote scripts, captures screenshots, exfiltrates files, cleans traces
- Attributed with moderate confidence to North Korea-linked Konni; themes target Ukraine-policy workers
- Infrastructure active since August 2026; no verified victim list published
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | dofamini.com.ua | lure URL prefix only; its ending is cut off. URL hxxps[://]dofamini[.]com[.]ua/media/CV_OlesiaTsvientukh_SocialResearcher_Sociologist_ |
| domain | github.com | ompromise (IoCs):- Type Indicator Description URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/ GitHub account listed in the source’ |
| domain | jaemoolding25863.elementfx.com | 5t6r7e8w9q0[.]medianewsonline[.]com Campaign domain. Domain jaemoolding25863[.]elementfx[.]com Source-listed network indicator. Domain zvwb1ep7i[.]onl |
| domain | kovalenko.dothome.co.kr | name Data-upload address shown in the source. URL hxxps[://]kovalenko[.]dothome[.]co[.]kr/media/A_Century_Long_Peace_Architecture_for_Ru PDF-vi |
| domain | login.php | . URL hxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/login[.]php?OKey=$env:userdomain&Areyou=cake&Who=$env:username Remote |
| domain | logout.php | . URL hxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/logout[.]php?OKey=$env:userdomain&Who=$env:username Data-upload addres |
Full article1,034 words · extracted from cybersecuritynews.com · click to collapse
A newly documented campaign targeting people and organizations focused on Ukraine uses document-themed Windows shortcuts to install a malware downloader called VelvetCake.
The goal appears to be gathering political and military intelligence about the war. The attackers likely send targeted emails with ZIP attachments.
Inside are shortcut files that look like PDFs about peace proposals, food prices and researcher resumes. Opening one runs code while displaying a decoy. Another route uses a modified video meeting installer.
SOCRadar said in a report shared with Cyber Security News (CSN) that its analysts identified the activity as Operation Conflict Compass.
The researchers associate it with Konni, a North Korea-linked espionage group, with moderate confidence. Infrastructure tied to the operation appeared as early as August 2026, but the report does not provide a verified victim count.
That distinction matters because the observed malware can gather system details, capture screens and send files out of an infected machine.
.webp)
Earlier reporting on TA406 attacks against Ukrainian government entities provides context for the group’s interest in Ukraine. The findings show a working surveillance chain, not confirmed losses.
Fake PDF Files Hide Konni Malware Campaign
These are not PDFs. They are Windows shortcut files, also called LNK files, packaged in ZIP archives as documents. Their subjects include a proposed framework for Russia-Ukraine peace, rising food prices connected to the Strait of Hormuz, and a social researcher’s resume.
Those choices point toward people working in diplomacy, policy research and nongovernmental organizations, although no victim list was published.
Attackers placed lures on a South Korean hosting service and a Ukrainian apparel website. Once a target opens the shortcut, it launches PowerShell to fetch additional components and a decoy document.
.webp)
The method echoes Konni campaigns using disguised shortcuts seen in South Korea. Here, the shortcut starts a script that creates a scheduled task, allowing the downloader to run repeatedly.
Researchers also found a modified meeting installer carrying a legitimate installer alongside the malicious components. They could not confirm how it reached targets, but assessed that a meeting invitation may have encouraged downloads.
A separate executable variant loads code directly from a remote server rather than leaving the main downloader on disk.
VelvetCake Enables Remote Espionage
After the shortcut runs, one downloaded script sets up a scheduled task that calls PowerShell every minute. Another delivers VelvetCake, a small downloader that connects to an attacker-controlled server, retrieves available scripts, runs them and sends back any resulting files.
It removes temporary material when the job is finished. This design lets operators change what the infected machine does without replacing the initial malware.
The repeated task turns short bursts of activity into an ongoing channel for remote instructions. The chain also resembles Kimsuky attacks using malicious shortcuts, where an apparently harmless document begins a longer infection.
One recovered follow-on script checked installed security software, system settings, network configuration, running processes, recent files and available drives.
.webp)
It also took a screenshot and sent the collected material to an external server before deleting local copies. Those findings demonstrate collection capability, but do not prove that every targeted organization experienced data theft.
Investigators linked the campaign to Konni through its Ukraine-focused themes, shortcut-based delivery, overlapping infrastructure and operator activity.
The assessment is not conclusive: a repository’s time-zone setting can support attribution, but cannot establish an operator’s location by itself. The report describes activity consistent with intelligence collection and stops short of identifying affected organizations.
Organizations handling sensitive Ukraine-related work should treat unexpected document archives and meeting installers with care.
Checking the real file type before opening attachments, watching for unusual scheduled tasks and reviewing PowerShell activity can expose this kind of infection. As earlier Konni phishing campaigns showed, a familiar document theme can hide the first step of a much larger intrusion.
Indicators of compromise (IoCs):-
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.