A newly documented campaign targeting people and organizations focused on Ukraine uses document-themed Windows shortcuts to install a malware downloader called VelvetCake.
The goal appears to be gathering political and military intelligence about the war. The attackers likely send targeted emails with ZIP attachments.
Inside are shortcut files that look like PDFs about peace proposals, food prices and researcher resumes. Opening one runs code while displaying a decoy. Another route uses a modified video meeting installer.
SOCRadar said in a report shared with Cyber Security News (CSN) that its analysts identified the activity as Operation Conflict Compass.
The researchers associate it with Konni, a North Korea-linked espionage group, with moderate confidence. Infrastructure tied to the operation appeared as early as August 2026, but the report does not provide a verified victim count.
That distinction matters because the observed malware can gather system details, capture screens and send files out of an infected machine.
Earlier reporting on TA406 attacks against Ukrainian government entities provides context for the group’s interest in Ukraine. The findings show a working surveillance chain, not confirmed losses.
Fake PDF Files Hide Konni Malware Campaign
These are not PDFs. They are Windows shortcut files, also called LNK files, packaged in ZIP archives as documents. Their subjects include a proposed framework for Russia-Ukraine peace, rising food prices connected to the Strait of Hormuz, and a social researcher’s resume.
Those choices point toward people working in diplomacy, policy research and nongovernmental organizations, although no victim list was published.
Attackers placed lures on a South Korean hosting service and a Ukrainian apparel website. Once a target opens the shortcut, it launches PowerShell to fetch additional components and a decoy document.
.webp)
The method echoes Konni campaigns using disguised shortcuts seen in South Korea. Here, the shortcut starts a script that creates a scheduled task, allowing the downloader to run repeatedly.
Researchers also found a modified meeting installer carrying a legitimate installer alongside the malicious components. They could not confirm how it reached targets, but assessed that a meeting invitation may have encouraged downloads.
A separate executable variant loads code directly from a remote server rather than leaving the main downloader on disk.
VelvetCake Enables Remote Espionage
After the shortcut runs, one downloaded script sets up a scheduled task that calls PowerShell every minute. Another delivers VelvetCake, a small downloader that connects to an attacker-controlled server, retrieves available scripts, runs them and sends back any resulting files.
It removes temporary material when the job is finished. This design lets operators change what the infected machine does without replacing the initial malware.
The repeated task turns short bursts of activity into an ongoing channel for remote instructions. The chain also resembles Kimsuky attacks using malicious shortcuts, where an apparently harmless document begins a longer infection.
One recovered follow-on script checked installed security software, system settings, network configuration, running processes, recent files and available drives.
.webp)
It also took a screenshot and sent the collected material to an external server before deleting local copies. Those findings demonstrate collection capability, but do not prove that every targeted organization experienced data theft.
Investigators linked the campaign to Konni through its Ukraine-focused themes, shortcut-based delivery, overlapping infrastructure and operator activity.
The assessment is not conclusive: a repository’s time-zone setting can support attribution, but cannot establish an operator’s location by itself. The report describes activity consistent with intelligence collection and stops short of identifying affected organizations.
Organizations handling sensitive Ukraine-related work should treat unexpected document archives and meeting installers with care.
Checking the real file type before opening attachments, watching for unusual scheduled tasks and reviewing PowerShell activity can expose this kind of infection. As earlier Konni phishing campaigns showed, a familiar document theme can hide the first step of a much larger intrusion.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| URL | hxxps[://]github[.]com/omskiwdcvoiuyfd0998/ | GitHub account listed in the source’s network indicators. |
| URL | hxxps[://]github[.]com/omskiwdcvoiuyfd0998/media | Source-listed GitHub URL; the PDF may cut off its ending. |
| URL | hxxps[://]github[.]com/omskiwdcvoiuyfd0998/medianews | Source-listed GitHub URL; the PDF may cut off its ending. |
| URL | hxxps[://]github[.]com/omskiwdcvoiuyfd0998/zoominstaller | Source-listed GitHub URL; the PDF may cut off its ending. |
| URL | hxxps[://]github[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefke | PDF-visible prefix only; do not use as a complete URL. |
| URL | hxxps[://]raw[.]githubusercontent[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkeu90djfkefh/refs/heads/main/LICENSE | Script staging address shown in the execution-chain text. |
| URL | hxxps[://]raw[.]githubusercontent[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkeu90djfkefh/refs/heads/main/okay[.]md | VelvetCake staging address shown in the execution-chain text. |
| URL | hxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/login[.]php?OKey=$env:userdomain&Areyou=cake&Who=$env:username | Remote-code request shown in the source. |
| URL | hxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/logout[.]php?OKey=$env:userdomain&Who=$env:username | Data-upload address shown in the source. |
| URL | hxxps[://]kovalenko[.]dothome[.]co[.]kr/media/A_Century_Long_Peace_Architecture_for_Ru | PDF-visible lure URL prefix only; its ending is cut off. |
| URL | hxxps[://]dofamini[.]com[.]ua/media/CV_OlesiaTsvientukh_SocialResearcher_Sociologist_Qu | PDF-visible lure URL prefix only; its ending is cut off. |
| Domain | p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com | Campaign domain. |
| Domain | jaemoolding25863[.]elementfx[.]com | Source-listed network indicator. |
| Domain | zvwb1ep7i[.]onlinewebshop[.]net | Source-listed network indicator. |
| IP address | 111[.]92[.]246[.]145 | VelvetCake server; the source describes a connection on port 12345. |
| Email address | omski00[@]outlook[.]com | Source-listed network indicator. |
| File name | update1.vbs | Downloaded persistence script. |
| File name | update1.ps1 | PowerShell file named in the scheduled-task description. |
| File name | update2.ps1 | Downloaded VelvetCake script. |
| Scheduled task | OneDriveUpdateScheduler | Task created for repeated execution. |
| SHA-256 | 297292d46d4f11fc801f5d6d01251735698a8419aa3196db7b3aa7bb8ea85cad | Source-listed host indicator. |
| SHA-256 | d398f11c236a59e44a9dff6f99af3aacefcb4a4bdf77bb7cf790cd0b13b0439a | Source-listed host indicator. |
| SHA-256 | 0db1e8a3075ffc2f5caa91abaeabb6ba4365ae0eda64d179374614a79e317733 | Source-listed host indicator. |
| SHA-256 | ec47a2101de4f1fc25995e775ddb48e20977081c4d885e6ff8fdfe9109d05495 | Source-listed host indicator. |
| SHA-256 | ac8df7baf7f1397a8c194840f6a5c1b0182088febde55f46d9f73ee8abc97c1d | Source-listed host indicator. |
| SHA-256 | e162d64d3e69cea868f62f63906098de310fad9fa1ca693409a65de89760eaaa | Source-listed host indicator. |
| SHA-256 | 9f2cc22a74499b0a5b39a8f4732ff74d7338addd972387302016ba5a026936ac | Source-listed host indicator. |
| SHA-256 | d3e599af47b110ab526ee38edaae68df3d8ab257e689e6f6f84d6db7d3ba5937 | Source-listed host indicator. |
| SHA-256 | 467660ef31b8ec248ae434fdee0a68de5098bcfd08776a4004ccbdcd7904bd37 | Source-listed host indicator. |
| SHA-256 | c88165d943f59014d668818d99d9819e6d295d355c4e935ad7a2380bbe32ccc | Reproduced as printed; only 63 characters are visible in the supplied PDF, so this is not a usable complete SHA-256 value. |
| SHA-256 | cd0a48b5ebd946ea2b8964e9d6a73a48d73777fdb7c8da99c28404150b560f6 | Reproduced as printed; only 63 characters are visible in the supplied PDF, so this is not a usable complete SHA-256 value. |
| SHA-256 | e41fdf41e6f5d089d1b8d7ea6f6a5c76760fe2a553c8ebc47601ebeca01311e1 | Source-listed host indicator. |
| SHA-256 | 76e9bdf193b3127623b674efdf3f0e3585932af33c9c85a3d6375d369de0e12a | Source-listed host indicator. |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

