Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs

Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs

Posted on September 24, 2026 By CWS

Recent cyberattacks using fake PDF files have targeted organizations with interests in Ukraine. These attacks are linked to the Konni malware campaign, which employs Windows shortcuts to deploy a downloader known as VelvetCake. This operation is primarily aimed at collecting sensitive political and military information concerning the ongoing conflict in Ukraine.

Uncovering Operation Conflict Compass

The cybersecurity firm SOCRadar has identified these activities as part of Operation Conflict Compass. According to their report shared with Cyber Security News, this operation is associated with the Konni espionage group, which has ties to North Korea. The campaign’s infrastructure was first observed in August 2026, although specific victim details remain unverified.

The attackers commonly use emails with ZIP file attachments. These ZIP files contain LNK files masquerading as PDFs, with topics ranging from peace proposals to economic analyses. Once opened, these files execute malicious code while displaying a harmless decoy document.

Technical Execution and Methods

The campaign utilizes a South Korean hosting service and a Ukrainian apparel website to lure victims. When a target opens a shortcut file, it triggers PowerShell commands to download additional malicious components. Another method involves a tampered video conferencing installer, suggesting that meeting invitations may have facilitated these downloads.

SOCRadar reports that the operation’s tactics mimic previous Konni campaigns in South Korea. The malware creates scheduled tasks that regularly execute the downloader, ensuring persistent access to the infected system. A variant of the attack even executes code directly from a remote server, bypassing local storage.

Implications and Precautions

The VelvetCake downloader is a crucial component, designed to connect with an attacker-controlled server, execute scripts, and exfiltrate data. It periodically removes traces of its activity, allowing the attackers to adjust their strategy without altering the initial malware.

Organizations dealing with sensitive Ukraine-related matters should exercise caution with unexpected file attachments and installers. Verifying file types, monitoring new scheduled tasks, and reviewing PowerShell activities are crucial steps to detect and prevent such intrusions. Although direct data theft remains unconfirmed, the campaign’s design suggests robust surveillance capabilities.

The links between Konni and this campaign are drawn from thematic focuses on Ukraine and similarities in delivery methods. However, definitive attribution is complicated, as infrastructure overlaps do not conclusively pinpoint the responsible actors. Organizations must remain vigilant against these sophisticated cyber threats.

Cyber Security News Tags:Cybersecurity, Espionage, fake PDFs, Konni, LNK files, Malware, North Korea, Operation Conflict Compass, Ukraine, VelvetCake

Post navigation

Previous Post: Agentic Remediation: Closing the Loop in Cybersecurity
Next Post: Ukrainian Sites Hacked for Psychedelic Stealer Distribution

Related Posts

Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories Cyber Security News
State Hackers Exploit RDP Servers to Deploy Stealthy Malware State Hackers Exploit RDP Servers to Deploy Stealthy Malware Cyber Security News
PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems PDFSIDER Malware Actively Used by Threat Actors to Bypass Antivirus and EDR Systems Cyber Security News
11 Best Cloud Access Security Broker Software (CASB) 11 Best Cloud Access Security Broker Software (CASB) Cyber Security News
WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private Cyber Security News
DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems DDRop Attack Exposes Vulnerabilities in Intel and AMD Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Websites for Data Collection Concerns
  • Ukrainian Sites Hacked for Psychedelic Stealer Distribution
  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Websites for Data Collection Concerns
  • Ukrainian Sites Hacked for Psychedelic Stealer Distribution
  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark