Piece of news of the day
ADVANCED SECURITY EUROPA
EOODNorth Korean Hackers Exploit KakaoTalk to Spread Malware Through Social Engineering
Mar 17, 2026North Korean threat actors identified as the hacking group Konni have been using spear-phishing emails to compromise targets and gain access to their KakaoTalk desktop application to distribute malicious payloads to specific contacts.
The attack involved tricking victims with a fake email appointing them as a North Korean human rights lecturer, leading to the installation of remote access malware on the victim's system.
The threat actor remained undetected on the compromised host for an extended period, stealing internal documents and sensitive information.
The malware, named EndRAT, allowed the attacker to remotely control the compromised system.
The attacker also used the victim's KakaoTalk application to distribute malicious files to contacts, turning them into intermediaries for further attacks.
This multi-stage attack operation utilized various RAT families and utilized deceptive tactics to propagate the malware.

