North Korean state hackers have launched a fresh espionage operation against Ukraine-focused targets, using war-fatigue narratives and fake peace proposals to plant a stealthy new malware strain researchers have named VelvetCake.
The SOCRadar Threat Research Unit (STRU) has uncovered “Operation Conflict Compass,” a cyberespionage campaign attributed with moderate confidence to Konni, a DPRK-nexus threat actor operating under North Korea’s General Reconnaissance and Information Bureau and widely considered a subgroup of the larger Kimsuky umbrella.
Independent researchers first surfaced the campaign on X in early September 2026, and it traces its infrastructure back to at least August 3, 2026.
North Korea’s Konni Hackers Use Fake Ukraine
Konni’s targets appear to be diplomatic entities, think tanks, and NGOs tracking the Russia-Ukraine war’s trajectory.
The group’s chosen bait is telling: a purported academic book on a “Century-Long Peace Architecture” for the conflict, a Ukrainian social researcher’s CV, and a Ukrainian-language document analyzing how the Strait of Hormuz crisis threatens global food and fertilizer supplies.
Each lure was packaged as a PDF but delivered as a malicious LNK file hidden inside a ZIP attachment, hosted on legitimate-looking infrastructure including a South Korean web host, Dothome, and a Ukrainian apparel company’s compromised site, Dofamini.
Opening the disguised LNK triggers a PowerShell command that pulls two files from a GitHub repository into the victim’s AppData folder: a VBScript that registers a scheduled task deceptively named “OneDriveUpdateScheduler,” and a PowerShell downloader that calls VelvetCake.
The scheduled task re-executes VelvetCake every 60 seconds, turning what starts as a one-time infection into a near-continuous tasking channel.
VelvetCake itself carries no fixed toolkit. Instead, it opens a raw TCP socket to a command-and-control server at 111.92.246.145 on port 12345, authenticates with a hardcoded password, and requests a live inventory of available scripts.
Based on filename patterns, it downloads configuration files or executable PowerShell modules on demand, runs them, harvests any resulting output, and exfiltrates it before deleting all traces.
Researchers also observed the same payloads bundled inside a trojanized Zoom installer, suggesting Konni lured some victims with fake meeting invitations.
A recovered second-stage script showed the operators using VelvetCake to fingerprint antivirus software, enumerate processes and recent files, map disk drives, and capture full-screen screenshots, all of which they exfiltrated to a free subdomain hosted on medianewsonline.com.
STRU’s attribution rests on several overlapping threads: the Ukraine-specific targeting matches Konni’s documented history (also tracked as TA406), the C2 URL formatting mirrors patterns seen in past Kimsuky and Konni campaigns using services like mywebcommunity.org and mygamesonline.org, and GitHub commit timestamps for the staging repository cluster heavily around a UTC+9 workday with a midday break consistent with Korean working hours.
Sloppy hardcoded artifacts, like the plaintext password “MySecurePass123” and a static port number, hint at rushed or possibly AI-assisted development.
With North Korean troops reportedly still deployed alongside Russian forces, Pyongyang has a clear strategic incentive to monitor how the war is trending, and Konni’s minimalist, server-driven malware design lets operators adapt tasking on the fly without redeploying payloads.
Organizations working on Ukraine policy, humanitarian response, or peace negotiations should treat LNK-in-ZIP attachments and unsolicited Zoom installer links as high-risk, and hunt for the “OneDriveUpdateScheduler” scheduled task as a concrete detection opportunity.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.