logo

Cisco's Talos Intelligence Group Blog: KONNI: A Malware Under The Radar For Years

ID: f2c217c4-94a1-413b-bc3b-5bba9a615d2a

STIX ID: report--f2c217c4-94a1-413b-bc3b-5bba9a615d2a

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2017-05-05

Last Modified Date: 2017-05-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Talos' analysis describes the KONNI RAT and a series of targeted campaigns (2014–2017) that used malicious .src attachments and convincing decoy Office/JPG documents to deploy a multi-stage RAT capable of stealing browser data, keystrokes, files, taking screenshots, and executing commands; the report includes C2 domains, PHP endpoints, dropped filenames, numerous SHA256 sample hashes, and recommended detection/mitigation coverage.