Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


A newly documented campaign targeting people and organizations focused on Ukraine uses document-themed Windows shortcuts to install a malware downloader called VelvetCake.

The goal appears to be gathering political and military intelligence about the war. The attackers likely send targeted emails with ZIP attachments.

Inside are shortcut files that look like PDFs about peace proposals, food prices and researcher resumes. Opening one runs code while displaying a decoy. Another route uses a modified video meeting installer.

SOCRadar said in a report shared with Cyber Security News (CSN) that its analysts identified the activity as Operation Conflict Compass.

The researchers associate it with Konni, a North Korea-linked espionage group, with moderate confidence. Infrastructure tied to the operation appeared as early as August 2026, but the report does not provide a verified victim count.

That distinction matters because the observed malware can gather system details, capture screens and send files out of an infected machine.

Operation Conflict Compass attack chain (Source - SOCRadar)
Operation Conflict Compass attack chain (Source – SOCRadar)

Earlier reporting on TA406 attacks against Ukrainian government entities provides context for the group’s interest in Ukraine. The findings show a working surveillance chain, not confirmed losses.

Fake PDF Files Hide Konni Malware Campaign

These are not PDFs. They are Windows shortcut files, also called LNK files, packaged in ZIP archives as documents. Their subjects include a proposed framework for Russia-Ukraine peace, rising food prices connected to the Strait of Hormuz, and a social researcher’s resume.

Those choices point toward people working in diplomacy, policy research and nongovernmental organizations, although no victim list was published.

Attackers placed lures on a South Korean hosting service and a Ukrainian apparel website. Once a target opens the shortcut, it launches PowerShell to fetch additional components and a decoy document.

Execution chain of the malicious LNK (Source - SOCRadar)
Execution chain of the malicious LNK (Source – SOCRadar)

The method echoes Konni campaigns using disguised shortcuts seen in South Korea. Here, the shortcut starts a script that creates a scheduled task, allowing the downloader to run repeatedly.

Researchers also found a modified meeting installer carrying a legitimate installer alongside the malicious components. They could not confirm how it reached targets, but assessed that a meeting invitation may have encouraged downloads.

A separate executable variant loads code directly from a remote server rather than leaving the main downloader on disk.

VelvetCake Enables Remote Espionage

After the shortcut runs, one downloaded script sets up a scheduled task that calls PowerShell every minute. Another delivers VelvetCake, a small downloader that connects to an attacker-controlled server, retrieves available scripts, runs them and sends back any resulting files.

It removes temporary material when the job is finished. This design lets operators change what the infected machine does without replacing the initial malware.

The repeated task turns short bursts of activity into an ongoing channel for remote instructions. The chain also resembles Kimsuky attacks using malicious shortcuts, where an apparently harmless document begins a longer infection.

One recovered follow-on script checked installed security software, system settings, network configuration, running processes, recent files and available drives.

VelvetCake’s code excerpts (Source - SOCRadar)
VelvetCake’s code excerpts (Source – SOCRadar)

It also took a screenshot and sent the collected material to an external server before deleting local copies. Those findings demonstrate collection capability, but do not prove that every targeted organization experienced data theft.

Investigators linked the campaign to Konni through its Ukraine-focused themes, shortcut-based delivery, overlapping infrastructure and operator activity.

The assessment is not conclusive: a repository’s time-zone setting can support attribution, but cannot establish an operator’s location by itself. The report describes activity consistent with intelligence collection and stops short of identifying affected organizations.

Organizations handling sensitive Ukraine-related work should treat unexpected document archives and meeting installers with care.

Checking the real file type before opening attachments, watching for unusual scheduled tasks and reviewing PowerShell activity can expose this kind of infection. As earlier Konni phishing campaigns showed, a familiar document theme can hide the first step of a much larger intrusion.

Indicators of compromise (IoCs):-

Type Indicator Description
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/ GitHub account listed in the source’s network indicators.
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/media Source-listed GitHub URL; the PDF may cut off its ending.
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/medianews Source-listed GitHub URL; the PDF may cut off its ending.
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/zoominstaller Source-listed GitHub URL; the PDF may cut off its ending.
URL hxxps[://]github[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefke PDF-visible prefix only; do not use as a complete URL.
URL hxxps[://]raw[.]githubusercontent[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkeu90djfkefh/refs/heads/main/LICENSE Script staging address shown in the execution-chain text.
URL hxxps[://]raw[.]githubusercontent[.]com/omskiwdcvoiuyfd0998/0ijnbjfke8djfefhkehhdkefkeu90djfkefh/refs/heads/main/okay[.]md VelvetCake staging address shown in the execution-chain text.
URL hxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/login[.]php?OKey=$env:userdomain&Areyou=cake&Who=$env:username Remote-code request shown in the source.
URL hxxp[://]p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com/logout[.]php?OKey=$env:userdomain&Who=$env:username Data-upload address shown in the source.
URL hxxps[://]kovalenko[.]dothome[.]co[.]kr/media/A_Century_Long_Peace_Architecture_for_Ru PDF-visible lure URL prefix only; its ending is cut off.
URL hxxps[://]dofamini[.]com[.]ua/media/CV_OlesiaTsvientukh_SocialResearcher_Sociologist_Qu PDF-visible lure URL prefix only; its ending is cut off.
Domain p1o2i3u4y5t6r7e8w9q0[.]medianewsonline[.]com Campaign domain.
Domain jaemoolding25863[.]elementfx[.]com Source-listed network indicator.
Domain zvwb1ep7i[.]onlinewebshop[.]net Source-listed network indicator.
IP address 111[.]92[.]246[.]145 VelvetCake server; the source describes a connection on port 12345.
Email address omski00[@]outlook[.]com Source-listed network indicator.
File name update1.vbs Downloaded persistence script.
File name update1.ps1 PowerShell file named in the scheduled-task description.
File name update2.ps1 Downloaded VelvetCake script.
Scheduled task OneDriveUpdateScheduler Task created for repeated execution.
SHA-256 297292d46d4f11fc801f5d6d01251735698a8419aa3196db7b3aa7bb8ea85cad Source-listed host indicator.
SHA-256 d398f11c236a59e44a9dff6f99af3aacefcb4a4bdf77bb7cf790cd0b13b0439a Source-listed host indicator.
SHA-256 0db1e8a3075ffc2f5caa91abaeabb6ba4365ae0eda64d179374614a79e317733 Source-listed host indicator.
SHA-256 ec47a2101de4f1fc25995e775ddb48e20977081c4d885e6ff8fdfe9109d05495 Source-listed host indicator.
SHA-256 ac8df7baf7f1397a8c194840f6a5c1b0182088febde55f46d9f73ee8abc97c1d Source-listed host indicator.
SHA-256 e162d64d3e69cea868f62f63906098de310fad9fa1ca693409a65de89760eaaa Source-listed host indicator.
SHA-256 9f2cc22a74499b0a5b39a8f4732ff74d7338addd972387302016ba5a026936ac Source-listed host indicator.
SHA-256 d3e599af47b110ab526ee38edaae68df3d8ab257e689e6f6f84d6db7d3ba5937 Source-listed host indicator.
SHA-256 467660ef31b8ec248ae434fdee0a68de5098bcfd08776a4004ccbdcd7904bd37 Source-listed host indicator.
SHA-256 c88165d943f59014d668818d99d9819e6d295d355c4e935ad7a2380bbe32ccc Reproduced as printed; only 63 characters are visible in the supplied PDF, so this is not a usable complete SHA-256 value.
SHA-256 cd0a48b5ebd946ea2b8964e9d6a73a48d73777fdb7c8da99c28404150b560f6 Reproduced as printed; only 63 characters are visible in the supplied PDF, so this is not a usable complete SHA-256 value.
SHA-256 e41fdf41e6f5d089d1b8d7ea6f6a5c76760fe2a553c8ebc47601ebeca01311e1 Source-listed host indicator.
SHA-256 76e9bdf193b3127623b674efdf3f0e3585932af33c9c85a3d6375d369de0e12a Source-listed host indicator.

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Fake PDF Files Hide Konni Malware Campaign Targeting Ukraine Organizations appeared first on Cyber Security News.