Konni Deploys EndRAT via Phishing, Leveraging KakaoTalk to Spread Malware

The North Korean hacking group Konni uses spear-phishing emails and the KakaoTalk messaging platform to deploy EndRAT, a remote access trojan, and propagate malware across compromised networks.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region3 min read
North Korean Konni group using phishing emails and KakaoTalk to propagate EndRAT malware.

North Korean Konni group using phishing emails and KakaoTalk to propagate EndRAT malware.

North Korean threat actors linked to the hacking group Konni have been observed targeting victims with sophisticated phishing campaigns. These attacks aim to compromise endpoints and exploit the victim’s KakaoTalk desktop application to propagate malware to selected contacts.

Initial Access via Spear-Phishing

According to the Genians Security Center, the attack begins with a spear-phishing email disguised as a notice appointing the recipient as a North Korean human rights lecturer [https://www.genians.com/threat-intelligence].

Upon opening a ZIP attachment containing a malicious Windows shortcut (LNK file), the victim executes a remote access trojan (RAT) payload. This enables the malware to remain persistent on the endpoint while exfiltrating sensitive internal documents and other valuable data.

Multi-Stage Malware Deployment

The downloaded malware, written in AutoIt, is identified as EndRAT (aka EndClient RAT). It provides attackers with:

  • File management and data transfer
  • Remote shell access
  • Persistence on the infected system

Analysis of affected systems has also revealed other RAT families, including RftRAT and RemcosRAT, indicating that multiple malware tools were deployed to increase operational resilience.

Abuse of KakaoTalk for Propagation

A distinguishing feature of this campaign is the exploitation of the victim’s installed KakaoTalk application to distribute additional malicious ZIP files to selected contacts. By turning compromised users into intermediaries, Konni extends the attack’s reach beyond initial phishing targets.

The malware disguises filenames as North Korea-related content, tricking recipients into opening the files, which triggers the next stage of infection.

In November 2025, Konni had previously leveraged KakaoTalk chat sessions to send malware payloads while simultaneously initiating remote wipes of Android devices using stolen Google credentials.

Attack Mechanism Overview

  1. Spear-phishing email with ZIP attachment containing LNK file
  2. Execution of LNK downloads EndRAT from an external server
  3. Scheduled tasks ensure persistence
  4. PDF decoy displayed to distract the user
  5. Infected KakaoTalk used to propagate malware to select contacts

Cybersecurity Implications

Genians assesses the campaign as multi-stage and highly targeted, combining:

  • Long-term endpoint persistence
  • Information theft
  • Account-based redistribution using trusted applications

Security professionals advise vigilance against phishing campaigns, careful handling of ZIP and LNK attachments, and monitoring messaging applications for anomalous activity .

Final Insight

The Konni EndRAT campaign underscores the growing sophistication of North Korean cyber operations, particularly in using trusted communication channels like KakaoTalk to multiply infections and exploit existing social trust for malicious ends.

Organizations and users should:

  • Keep messaging apps and endpoints updated
  • Avoid opening suspicious attachments
  • Monitor for unusual account behavior
  • Educate personnel on social engineering tactics

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.