Skip to main content

Konni Hackers Target Ukraine With Malicious LNK Files and VelvetCake PowerShell Malware

0
Medium
Published: 09/24/2026 (09/24/2026, 12:40:35 UTC)
Source: AlienVault OTX General

Description

North Korea-linked threat actors are conducting Operation Conflict Compass, targeting individuals and organizations focused on Ukraine using spear-phishing emails with malicious ZIP attachments. These contain LNK files disguised as PDFs with themes related to Russia-Ukraine peace plans, Ukrainian research, and geopolitical issues. When executed, the shortcuts retrieve malicious files from GitHub, deploying VBScript to establish persistence via scheduled tasks and delivering VelvetCake, a lightweight PowerShell-based task runner. VelvetCake contacts command-and-control infrastructure to download and execute additional scripts that perform reconnaissance, collect system information, enumerate security software, and capture screenshots. The campaign also utilized trojanized Zoom installers and leveraged infrastructure in South Korea and Ukraine, with activity observed since early August 2026 targeting diplomatic entities, think tanks, and NGOs.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 19:48:24 UTC

Technical Analysis

This campaign by North Korea-linked threat actors involves spear-phishing emails with malicious ZIP attachments containing LNK files masquerading as PDFs themed around Russia-Ukraine peace plans and geopolitical topics. When executed, these LNK files retrieve malicious VBScript from GitHub, which establishes persistence through scheduled tasks and deploys VelvetCake, a PowerShell-based task runner. VelvetCake connects to command-and-control infrastructure to download and run additional scripts that conduct reconnaissance, gather system information, enumerate security software, and capture screenshots. The campaign also employs trojanized Zoom installers and leverages infrastructure located in South Korea and Ukraine. The threat actor group, identified as Opal Sleet, has been active since early August 2026, focusing on Ukrainian diplomatic and research targets.

Potential Impact

The campaign enables threat actors to maintain persistence on compromised systems, perform detailed reconnaissance, collect sensitive system and security information, and capture screenshots, potentially exposing confidential data. The use of spear-phishing and trojanized legitimate software installers increases the risk of successful compromise of targeted organizations. The targeting of diplomatic entities, think tanks, and NGOs in Ukraine suggests potential espionage and intelligence-gathering objectives.

Defensive Guidance

No official patch or remediation is indicated for this campaign. Organizations should be aware of spear-phishing attempts using LNK files disguised as PDFs and malicious ZIP attachments themed around geopolitical topics. Users should avoid opening unexpected attachments and verify the authenticity of software installers such as Zoom. Monitoring for scheduled tasks created without authorization and unusual PowerShell activity may help detect infections. Since this is an active campaign, applying email filtering and user awareness training focused on spear-phishing is recommended.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://cyberpress.org/konni-targets-ukraine-with-velvetcake/"]
Adversary
Opal Sleet
Pulse Id
6ab51a43ec94931b637c0607

Indicators of Compromise

Domain

ValueDescriptionCopy
domainp1o2i3u4y5t6r7e8w9q0.medianewsonline.com
—

Url

ValueDescriptionCopy
urlhttp://111.92.246.145:12345
—

Threat ID: 6ab57aedf7a7c54106bff42c

Added to database: 09/24/2026, 19:33:01 UTC

Last enriched: 09/24/2026, 19:48:24 UTC

Last updated: 09/25/2026, 04:08:49 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses