Konni's Operation Conflict Compass Targets Ukraine-Focused Diplomatic, Policy, and NGO Actors with VelvetCake Malware via Fake PDF Lures
North Korea-linked Konni (attributed with moderate confidence; also tracked as TA406 and Opal Sleet) is running the Conflict Compass espionage campaign against Ukraine-focused diplomatic, policy, NGO, and defense audiences, using LNK files disguised as PDFs…
SOCRadar documents Operation Conflict Compass, a cyberespionage campaign attributed with moderate confidence to North Korea-linked Konni (also tracked as TA406 and Opal Sleet within the Kimsuky umbrella). Spear-phishing ZIP archives contain Windows LNK shortcuts disguised as PDFs — including peace-proposal, researcher résumé, and food-price disruption lures — targeting audiences working on Ukraine diplomacy, policy research, NGOs, and defense. Opening a lure launches JavaScript and PowerShell, which download a VBScript persistence component and the VelvetCake downloader from GitHub. A scheduled task named OneDriveUpdateScheduler relaunches a lightweight task runner every minute; the runner fetches PowerShell modules over raw TCP port 12345, collects host and network data plus screenshots, exfiltrates results to attacker infrastructure, and deletes local artifacts. A trojanized Zoom installer variant was also used in the operation. Infrastructure tied to the campaign appeared as early as August 2026, but no verified victim count has been published. All three reports are consistent on attribution and mechanics; the only nuance is that SOCRadar states the Konni link with moderate confidence.
- Campaign named Operation Conflict Compass by SOCRadar; attributed with moderate confidence to North Korea-linked Konni, also tracked as TA406 and Opal Sleet within the Kimsuky umbrella.
- Targets Ukraine-focused diplomatic, policy research, NGO, and defense audiences.
- Infection vector: spear-phishing ZIP archives containing Windows LNK shortcuts disguised as PDFs, with lures themed around peace proposals, a researcher résumé, and food-price disruption.
- Initial execution uses JavaScript and PowerShell; PowerShell downloads a VBScript persistence component and the VelvetCake downloader from GitHub.
- Persistence via a scheduled task named OneDriveUpdateScheduler that relaunches a lightweight task runner every minute.
- VelvetCake fetches PowerShell task modules over raw TCP port 12345, collects host and network data plus screenshots, exfiltrates results, and deletes local artifacts.
- A trojanized Zoom installer variant was also used in the campaign.
- Infrastructure tied to the operation appeared as early as August 2026; no verified victim count or victim list has been published.
Coverage timelineoldest first · each row is one article
- · 4d agoOperation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures
SOCRadar· 65
Konni APT targets Ukraine with malicious LNK lures in 'Conflict Compass' campaign, using JavaScript and PowerShell for initial access.
- · 2d agoOperation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
GBHackers· 76
North Korea-linked Konni deployed VelvetCake PowerShell malware against Ukraine-focused targets via malicious LNK files.
- · 2d agoFake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations
Cyber Security News· 55