CyberSecurityNews

Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations


A newly documented campaign targeting people and organizations focused on Ukraine uses document-themed Windows shortcuts to install a malware downloader called VelvetCake.

The goal appears to be gathering political and military intelligence about the war. The attackers likely send targeted emails with ZIP attachments.

Inside are shortcut files that look like PDFs about peace proposals, food prices and researcher resumes. Opening one runs code while displaying a decoy. Another route uses a modified video meeting installer.

SOCRadar said in a report shared with Cyber Security News (CSN) that its analysts identified the activity as Operation Conflict Compass.

The researchers associate it with Konni, a North Korea-linked espionage group, with moderate confidence. Infrastructure tied to the operation appeared as early as August 2026, but the report does not provide a verified victim count.

That distinction matters because the observed malware can gather system details, capture screens and send files out of an infected machine.

Operation Conflict Compass attack chain (Source – SOCRadar)

Earlier reporting on TA406 attacks against Ukrainian government entities provides context for the group’s interest in Ukraine. The findings show a working surveillance chain, not confirmed losses.

Fake PDF Files Hide Konni Malware Campaign

These are not PDFs. They are Windows shortcut files, also called LNK files, packaged in ZIP archives as documents. Their subjects include a proposed framework for Russia-Ukraine peace, rising food prices connected to the Strait of Hormuz, and a social researcher’s resume.

Those choices point toward people working in diplomacy, policy research and nongovernmental organizations, although no victim list was published.

Attackers placed lures on a South Korean hosting service and a Ukrainian apparel website. Once a target opens the shortcut, it launches PowerShell to fetch additional components and a decoy document.

Execution chain of the malicious LNK (Source - SOCRadar)
Execution chain of the malicious LNK (Source – SOCRadar)

The method echoes Konni campaigns using disguised shortcuts seen in South Korea. Here, the shortcut starts a script that creates a scheduled task, allowing the downloader to run repeatedly.

Researchers also found a modified meeting installer carrying a legitimate installer alongside the malicious components. They could not confirm how it reached targets, but assessed that a meeting invitation may have encouraged downloads.

A separate executable variant loads code directly from a remote server rather than leaving the main downloader on disk.

VelvetCake Enables Remote Espionage

After the shortcut runs, one downloaded script sets up a scheduled task that calls PowerShell every minute. Another delivers VelvetCake, a small downloader that connects to an attacker-controlled server, retrieves available scripts, runs them and sends back any resulting files.

It removes temporary material when the job is finished. This design lets operators change what the infected machine does without replacing the initial malware.

The repeated task turns short bursts of activity into an ongoing channel for remote instructions. The chain also resembles Kimsuky attacks using malicious shortcuts, where an apparently harmless document begins a longer infection.

One recovered follow-on script checked installed security software, system settings, network configuration, running processes, recent files and available drives.

VelvetCake’s code excerpts (Source - SOCRadar)
VelvetCake’s code excerpts (Source – SOCRadar)

It also took a screenshot and sent the collected material to an external server before deleting local copies. Those findings demonstrate collection capability, but do not prove that every targeted organization experienced data theft.

Investigators linked the campaign to Konni through its Ukraine-focused themes, shortcut-based delivery, overlapping infrastructure and operator activity.

The assessment is not conclusive: a repository’s time-zone setting can support attribution, but cannot establish an operator’s location by itself. The report describes activity consistent with intelligence collection and stops short of identifying affected organizations.

Organizations handling sensitive Ukraine-related work should treat unexpected document archives and meeting installers with care.

Checking the real file type before opening attachments, watching for unusual scheduled tasks and reviewing PowerShell activity can expose this kind of infection. As earlier Konni phishing campaigns showed, a familiar document theme can hide the first step of a much larger intrusion.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
URLhxxps[://]github[.]com/omskiwdcvoiuyfd0998/GitHub account listed in the source’s network indicators.
URLhxxps[://]github[.]com/omskiwdcvoiuyfd0998/mediaSource-listed GitHub URL; the PDF may cut off its ending.
URLhxxps[://]github[.]com/omskiwdcvoiuyfd0998/medianewsSource-listed GitHub URL; the PDF may cut off its ending.
URLhxxps[://]github[.]com/omskiwdcvoiuyfd0998/zoominstallerSource-listed GitHub URL; the PDF may cut off its ending.
URLhxxps[://]github[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkePDF-visible prefix only; do not use as a complete URL.
URLhxxps[://]raw[.]githubusercontent[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkeu90djfkefh/refs/heads/main/LICENSEScript staging address shown in the execution-chain text.
URLhxxps[://]raw[.]githubusercontent[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkeu90djfkefh/refs/heads/main/okay[.]mdVelvetCake staging address shown in the execution-chain text.
URLhxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/login[.]php?OKey=$env:userdomain&Areyou=cake&Who=$env:usernameRemote-code request shown in the source.
URLhxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/logout[.]php?OKey=$env:userdomain&Who=$env:usernameData-upload address shown in the source.
URLhxxps[://]kovalenko[.]dothome[.]co[.]kr/media/A_Century_Long_Peace_Architecture_for_RuPDF-visible lure URL prefix only; its ending is cut off.
URLhxxps[://]dofamini[.]com[.]ua/media/CV_OlesiaTsvientukh_SocialResearcher_Sociologist_QuPDF-visible lure URL prefix only; its ending is cut off.
Domainp1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]comCampaign domain.
Domainjaemoolding25863[.]elementfx[.]comSource-listed network indicator.
Domainzvwb1ep7i[.]onlinewebshop[.]netSource-listed network indicator.
IP address111[.]92[.]246[.]145VelvetCake server; the source describes a connection on port 12345.
Email addressomski00[@]outlook[.]comSource-listed network indicator.
File nameupdate1.vbsDownloaded persistence script.
File nameupdate1.ps1PowerShell file named in the scheduled-task description.
File nameupdate2.ps1Downloaded VelvetCake script.
Scheduled taskOneDriveUpdateSchedulerTask created for repeated execution.
SHA-256297292d46d4f11fc801f5d6d01251735698a8419aa3196db7b3aa7bb8ea85cadSource-listed host indicator.
SHA-256d398f11c236a59e44a9dff6f99af3aacefcb4a4bdf77bb7cf790cd0b13b0439aSource-listed host indicator.
SHA-2560db1e8a3075ffc2f5caa91abaeabb6ba4365ae0eda64d179374614a79e317733Source-listed host indicator.
SHA-256ec47a2101de4f1fc25995e775ddb48e20977081c4d885e6ff8fdfe9109d05495Source-listed host indicator.
SHA-256ac8df7baf7f1397a8c194840f6a5c1b0182088febde55f46d9f73ee8abc97c1dSource-listed host indicator.
SHA-256e162d64d3e69cea868f62f63906098de310fad9fa1ca693409a65de89760eaaaSource-listed host indicator.
SHA-2569f2cc22a74499b0a5b39a8f4732ff74d7338addd972387302016ba5a026936acSource-listed host indicator.
SHA-256d3e599af47b110ab526ee38edaae68df3d8ab257e689e6f6f84d6db7d3ba5937Source-listed host indicator.
SHA-256467660ef31b8ec248ae434fdee0a68de5098bcfd08776a4004ccbdcd7904bd37Source-listed host indicator.
SHA-256c88165d943f59014d668818d99d9819e6d295d355c4e935ad7a2380bbe32cccReproduced as printed; only 63 characters are visible in the supplied PDF, so this is not a usable complete SHA-256 value.
SHA-256cd0a48b5ebd946ea2b8964e9d6a73a48d73777fdb7c8da99c28404150b560f6Reproduced as printed; only 63 characters are visible in the supplied PDF, so this is not a usable complete SHA-256 value.
SHA-256e41fdf41e6f5d089d1b8d7ea6f6a5c76760fe2a553c8ebc47601ebeca01311e1Source-listed host indicator.
SHA-25676e9bdf193b3127623b674efdf3f0e3585932af33c9c85a3d6375d369de0e12aSource-listed host indicator.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link