$ techbeacon▋
Darkweb

North Korean-linked Group Uses Fake PDF Shortcuts to Deploy VelvetCake Malware in Ukraine Target Campaign

North Korean-linked Group Uses Fake PDF Shortcuts to Deploy VelvetCake Malware in Ukraine Target Campaign

A cyber‑espionage campaign identified as Operation Conflict Compass is actively delivering a PowerShell‑based backdoor called VelvetCake to organizations that monitor or support Ukraine. The campaign, observed by the SOCRadar Threat Research Unit, relies on Windows shortcut (LNK) files that are crafted to look like PDF documents.

The malicious shortcuts are typically shared via email or file‑transfer services, where the filename ends with .pdf but the underlying file type is an LNK. When a user clicks the icon, Windows processes the shortcut and launches a hidden PowerShell script that fetches the payload from a remote server. Because the file appears to be a benign PDF, many users and basic security filters overlook it.

VelvetCake is a modular PowerShell framework that can download additional modules, execute commands, and exfiltrate data. Analysts have seen it establish encrypted communications with command‑and‑control infrastructure, allowing the operators to issue live instructions, harvest documents, and move laterally within compromised networks.

The group behind the operation, known in security circles as Konni, is believed to have ties to North Korea’s cyber‑warfare apparatus. The attribution is based on code reuse, infrastructure overlap, and previously documented activity linked to the regime. SOCRadar’s report adds to a growing body of evidence that state‑aligned actors are expanding their focus beyond traditional military targets to include political and civil‑society organizations in Ukraine.

Targeted entities include think tanks, NGOs, and media outlets that produce analysis on the conflict. By infiltrating these groups, the attackers can gather strategic intelligence, monitor public narratives, and potentially influence information flows. The timing coincides with heightened diplomatic activity and ongoing military engagements, underscoring the role of cyber‑espionage in modern geopolitical contests.

Security experts advise organizations to treat any unexpected PDF attachment with caution, verify file types before opening, and enforce strict execution policies for PowerShell scripts. Updating endpoint protection, applying the latest Windows patches, and employing email sandboxing can reduce the risk of LNK‑based attacks. As the campaign continues, researchers expect Konni to refine its delivery methods, making vigilance and threat‑intel sharing essential for defending against similar operations.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related