Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesStocksEarnInstitutionAI & More
North Korean Konni Hackers Deploy AI-Generated Malware to Target Devs

North Korean Konni Hackers Deploy AI-Generated Malware to Target Devs

CoinEditionCoinEdition2026/01/27 06:30
By:CoinEdition

Cybersecurity researchers have raised the alarm about a sophisticated new malware scheme. North Korea-linked hacking group Konni (also known as Opal Sleet and TA406) is leveraging AI-generated PowerShell malware to directly target blockchain developers and engineers.

Konni is a North Korean advanced persistent threat (APT) group that’s operated for at least a decade. While their targets lie in South Korea, Russia, Ukraine, and Europe regions, Asia-Pacific has also been added to the list.. 

The group is linked to other DPRK cyber groups, such as APT37 and Kimsuky, and has a track record of stealing money and secrets from banks, financial systems, and tech companies.

Experts, including researchers from Check Point, have shared detailed reports explaining how the Konni hack works step-by-step.

The hack starts with a Discord message containing a link. Clicking it downloads a compressed file that looks legitimate, holding both a PDF decoy and a harmful Windows shortcut file.

Related: Hackers Exploit GANA Payment for $3.1 Million on BSC Chain

Opening the shortcut file starts a PowerShell loader that unpacks more files. Among them are a fake DOCX document and a cabinet (CAB) archive holding a PowerShell backdoor, batch scripts, and an executable designed to bypass User Account Control (UAC). This allows the virus to stay installed on the victim’s computer.

Researchers note that the virus shows clear signs of being AI-generated. Its code is built in separate blocks, contains unusually neat comments, and uses strange placeholder text, which sets it apart from typical human-written malware.

The malicious software sets up an automated hourly task, disguised as a OneDrive startup task. This secretly unlocks and launches a PowerShell command in the computer’s memory. After the harmful part of the program runs, it cleans up some of its own files to cover its tracks.

(adsbygoogle = window.adsbygoogle || []).push({});

Unlike typical hacks that target random users, this attack is aimed directly at software developers and engineers who build crypto platforms. These individuals often have access to API keys, source code access, and private wallet keys. 

If hacked, they could give attackers control over important applications and large amounts of crypto. Researchers have seen this campaign mainly hitting targets in Japan, Australia, and India, showing that the hackers are deliberately going after new regions.

Related: CZ’s Stark Warning: One Click on a Fake Support Link Could Sink a Crypto Exchange

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

Talos Energy director Barbara J. Faulkenberry files initial beneficial ownership statement

Talos Energy director Barbara J. Faulkenberry filed an initial Form 3 statement dated Oct. 1, 2026. Disclaimer: This news brief was created by Public Technologies (PUBT) using generative artificial intelligence. While PUBT strives to provide accurate and timely information, this AI-generated content is for informational purposes only and should not be interpreted as financial, investment, or legal advice. Talos Energy Inc. published the original content used to generate this news brief via EDGAR, the Electronic Data Gathering, Analysis, and Retrieval system operated by the U.S. Securities and Exchange Commission (Ref. ID: 0001193125-26-418248), on October 08, 2026, and is solely responsible for the information contained therein.

Bitget•2026/10/09 01:05

Exchange Traded Funds Top 10 Volume Leaders

NET % VOL STOCK (Symbol) LAST CHG CHG 100s Direxion Semicon Br 3x SOXS 33.79 3.14 10.24 113,576,607 ProShares Bitcoin ETF BITO 10.93 -0.21 -1.89 112,012,221 Direxion Semicon Bl 3x SOXL 142.52 -16.39 -10.31 100,351,229 ProShares Sh Russell2001 RWM 14.43 0.01 0.07 77,482,048 GrShr 2x Sh NVDA Daily NVD 3.55 0.20 5.97 73,813,301 ProShares UltraPro QQQ TQQQ 80.23 -3.39 -4.05 65,485,124 ProSh UltraPro Shrt QQQ SQQQ 33.37 1.30 4.05 60,470,210 iShares Bitcoin Trust ETF IBIT 46.26 -0.95 -2.01 56,191,237 Direxion PLTR Bear 1X PLTD 4.50 -0.11 -2.39 52,552,250 SS Energy Sel SPDR XLE 65.24 1.88 2.97 50,492,628 (END) Dow Jones Newswires October 08, 2026 17:38 ET (21:38 GMT)

Dow Jones•2026/10/08 21:38

--Zoetis Keeps Quarterly Dividend at $0.53 a Share, Payable Dec. 1 to Holders of Record Oct. 30

04:46 PM EDT, 10/08/2026 (MT Newswires) -- Zoetis Keeps Quarterly Dividend at $0.53 a Share, Payable Dec. 1 to Holders of Record Oct. 30

MT newswire•2026/10/08 20:46