Cisco's Talos Intelligence Group Blog: KONNI: A Malware Under The Radar For Years
ID: f2c217c4-94a1-413b-bc3b-5bba9a615d2a
STIX ID: report--f2c217c4-94a1-413b-bc3b-5bba9a615d2a
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2017-05-05
Last Modified Date: 2017-05-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Talos' analysis describes the KONNI RAT and a series of targeted campaigns (2014–2017) that used malicious .src attachments and convincing decoy Office/JPG documents to deploy a multi-stage RAT capable of stealing browser data, keystrokes, files, taking screenshots, and executing commands; the report includes C2 domains, PHP endpoints, dropped filenames, numerous SHA256 sample hashes, and recommended detection/mitigation coverage.
