Recent cyberattacks using fake PDF files have targeted organizations with interests in Ukraine. These attacks are linked to the Konni malware campaign, which employs Windows shortcuts to deploy a downloader known as VelvetCake. This operation is primarily aimed at collecting sensitive political and military information concerning the ongoing conflict in Ukraine.
Uncovering Operation Conflict Compass
The cybersecurity firm SOCRadar has identified these activities as part of Operation Conflict Compass. According to their report shared with Cyber Security News, this operation is associated with the Konni espionage group, which has ties to North Korea. The campaign’s infrastructure was first observed in August 2026, although specific victim details remain unverified.
The attackers commonly use emails with ZIP file attachments. These ZIP files contain LNK files masquerading as PDFs, with topics ranging from peace proposals to economic analyses. Once opened, these files execute malicious code while displaying a harmless decoy document.
Technical Execution and Methods
The campaign utilizes a South Korean hosting service and a Ukrainian apparel website to lure victims. When a target opens a shortcut file, it triggers PowerShell commands to download additional malicious components. Another method involves a tampered video conferencing installer, suggesting that meeting invitations may have facilitated these downloads.
SOCRadar reports that the operation’s tactics mimic previous Konni campaigns in South Korea. The malware creates scheduled tasks that regularly execute the downloader, ensuring persistent access to the infected system. A variant of the attack even executes code directly from a remote server, bypassing local storage.
Implications and Precautions
The VelvetCake downloader is a crucial component, designed to connect with an attacker-controlled server, execute scripts, and exfiltrate data. It periodically removes traces of its activity, allowing the attackers to adjust their strategy without altering the initial malware.
Organizations dealing with sensitive Ukraine-related matters should exercise caution with unexpected file attachments and installers. Verifying file types, monitoring new scheduled tasks, and reviewing PowerShell activities are crucial steps to detect and prevent such intrusions. Although direct data theft remains unconfirmed, the campaign’s design suggests robust surveillance capabilities.
The links between Konni and this campaign are drawn from thematic focuses on Ukraine and similarities in delivery methods. However, definitive attribution is complicated, as infrastructure overlaps do not conclusively pinpoint the responsible actors. Organizations must remain vigilant against these sophisticated cyber threats.
