THE SOCRadar Threat Research Unit says the suspected North Korean group Konni, also tracked as TA406 and Opal Sleet, began a targeted cyber-espionage campaign in early August 2026 against foreign-policy think tanks, diplomatic organisations and Ukraine-focused NGOs. The operation used spear-phishing emails containing ZIP archives with Windows LNK shortcut files disguised as PDF documents. The lures included material about food prices and Strait of Hormuz tensions, Russia-Ukraine peace negotiations, and fake researchers’ CVs.
Opening a shortcut runs a hidden PowerShell command that retrieves scripts from GitHub. A VBScript establishes persistence through a scheduled task called “OneDrive Update Scheduler”, which launches a downloader every minute. This delivers VelvetCake, a lightweight task runner that connects to a command server over raw TCP sockets, authenticates with a hardcoded password and retrieves further tasks. Researchers also observed the components distributed through trojanised Zoom installers.
According to SOCRadar, VelvetCake executes PowerShell scripts in memory, monitors directories for output and uploads collected files before deleting temporary copies. Reconnaissance included antivirus and system inventories, network connections, running processes, recently accessed files and screenshots.
The report attributes the activity to Konni with moderate confidence, citing similarities to earlier LNK and VBScript campaigns, shared server naming conventions and GitHub activity aligned with UTC+9 working hours. It recommends blocking archive attachments containing executable shortcuts, investigating unauthorised scheduled tasks, monitoring unusual raw TCP connections and restricting unsigned scripts.