SOCRadar Threat Research Unit (STRU) has discovered a cyber-espionage campaign dubbed ‘Operation Conflict Compass’, attributed to the North Korea-aligned threat actor, tracked as Konni. The campaign, observed in early August 2026, appears focused on organizations and individuals connected to Ukraine, with the goal of collecting intelligence about the future direction of the Russia-Ukraine war.
The campaign involves spear-phishing emails containing ZIP archives with malicious LNK files disguised as PDF documents. The lures referenced topics including global food-price increases linked to the Strait of Hormuz situation, Russia-Ukraine peace negotiations, and resumes for social researchers. The themes suggest possible targeting of diplomatic organizations, think tanks, and NGOs.
When opened, the malicious LNK files launch a VBScript, which establishes persistence by creating a scheduled task. The task runs a PowerShell script approximately every minute.
The PowerShell payload, named VelvetCake, acts as a lightweight modular downloader and continuously retrieves additional PowerShell modules from attacker-controlled infrastructure and executes them.
The infrastructure used in the campaign included South Korean and Ukrainian websites for hosting malicious lures, GitHub for staging scripts, and the free-subdomain service Medianewsonline for command-and-control (C&C) activity.
STRU attributes the operation to Konni, also tracked as TA406 and Opal Sleet, based on several technical and operational indicators, including the targeting of Ukrainian entities, characteristics associated with VelvetCake, overlaps in command-and-control and staging infrastructure, and similarities in the actors' operating time zone.
Konni has been active since at least 2014 and is associated with North Korea's intelligence operations. The group is commonly linked to the broader Kimsuky threat-actor ecosystem and has targeted organizations involved in foreign policy, defense, and international diplomacy.