KONNI
S0356 · Windows
KONNI is a remote access tool that security researchers assess has been used by North Korean cyber actors since at least 2014. KONNI has significant code overlap with the NOKKI malware family, and has been linked to several suspected North Korean campaigns targeting political organizations in Russia, East Asia, Europe and the Middle East.
there is some evidence potentially linking KONNI to APT37.
ATT&CK S0356
Sigma rules0
YARA rules0
Live IOCs0