Koreaherald N. Korea-linked Konni Group Uses Naver, Google Ads for Malware Distribution
Article Content
Browse articles
A North Korea-linked hacking group, Konni, has executed a malware distribution campaign by exploiting advertising systems of Naver and Google. The campaign is categorized as an advanced persistent threat (APT) and is associated with Kimsuky and other hacking groups from Pyongyang, as reported by Genians Security Center.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (7)
Following this threat?
Track Kimsuky, Poseidon and Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
New ScreenConnect Flaw Enables Malware Spread via Rogue Clients ConnectWise has identified a critical vulnerability in ScreenConnect Remote Access affecting both cloud and on-premises deployments. The flaw, which impacts file transfer functionality, allows attackers to deploy rogue ScreenConnect clients that spread malware to connected systems. This malware is propagated through…
Kimsuky Hacking Group Uses AI Coding Agent for Malware Decoys The North Korea-linked hacking group Kimsuky has been confirmed to use an open-source AI coding agent named 'opencode' to create decoy documents for malware distribution. A South Korean security firm, Genians, reported that analysis of 13 malicious files revealed that these documents were disguised as financial and…