Skip to content
N. Korea-linked Konni Group Uses Naver, Google Ads for Malware Distribution

N. Korea-linked Konni Group Uses Naver, Google Ads for Malware Distribution

First seen 19 Jan 2026, 06:00 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A North Korea-linked hacking group, Konni, has executed a malware distribution campaign by exploiting advertising systems of Naver and Google. The campaign is categorized as an advanced persistent threat (APT) and is associated with Kimsuky and other hacking groups from Pyongyang, as reported by Genians Security Center.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (7)

Following this threat?

Track Kimsuky, Poseidon and Google in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed