{"id":4009,"date":"2022-02-01T01:21:29","date_gmt":"2022-02-01T06:21:29","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=4009"},"modified":"2022-02-01T01:21:29","modified_gmt":"2022-02-01T06:21:29","slug":"konni-rat-returns-more-stealthy-and-dangerous","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/","title":{"rendered":"Konni RAT returns more stealthy and dangerous"},"content":{"rendered":"\n<p>Konni RAT, was detected in 2014 and through phishing-type campaigns begins the distribution phase with the use of Microsoft office documents that contain embedded malicious macros, which must be enabled by the user, unfortunately a cyber espionage group with links with North Korea it has re-emerged with a stealthier variant of Konni to attack political institutions located in Russia and South Korea.<\/p>\n\n\n\n<p>The most recent intrusions staged by the group, which is believed to operate under the group Kimsuky, involved targeting the Russian Federation&#8217;s Ministry of Foreign Affairs (MID) with New Year&#8217;s lures to compromise Windows systems with malware.<\/p>\n\n\n\n<p>Infections, as with other such attacks, begin with a malicious Microsoft Office document which, when opened, initiates a multi-stage process involving multiple moving parts that help attackers elevate privileges, evade detection and ultimately implement Konni RAT. payload on compromised systems.<\/p>\n\n\n\n<p>A new addition to the existing backdoor capabilities is the transition from Base64 encoding to AES encryption to protect your strings and obfuscate their true purpose. On top of that, the various support files removed for easy compromise are now also encrypted using AES.<\/p>\n\n\n\n<p>Updates to these types of threats are an example of how quickly actors can develop their tactics and techniques to create something powerful and effective that can get past layers of security and detection and that is why staying grounded and cool is essential to avoid this kind of problems.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4010,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-4009","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Konni RAT returns more stealthy and dangerous - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Konni RAT returns more stealthy and dangerous - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2022-02-01T06:21:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/Konni.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"450\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"Konni RAT returns more stealthy and dangerous\",\"datePublished\":\"2022-02-01T06:21:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/\"},\"wordCount\":241,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Konni.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/\",\"name\":\"Konni RAT returns more stealthy and dangerous - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Konni.jpg\",\"datePublished\":\"2022-02-01T06:21:29+00:00\",\"description\":\"Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Konni.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/02\\\/Konni.jpg\",\"width\":800,\"height\":450},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/konni-rat-returns-more-stealthy-and-dangerous\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Konni RAT returns more stealthy and dangerous\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Konni RAT returns more stealthy and dangerous - Truxgo Server Blog","description":"Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/","og_locale":"es_MX","og_type":"article","og_title":"Konni RAT returns more stealthy and dangerous - Truxgo Server Blog","og_description":"Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT...","og_url":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/","og_site_name":"Truxgo Server Blog","article_published_time":"2022-02-01T06:21:29+00:00","og_image":[{"width":800,"height":450,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/Konni.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"Konni RAT returns more stealthy and dangerous","datePublished":"2022-02-01T06:21:29+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/"},"wordCount":241,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/Konni.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/","url":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/","name":"Konni RAT returns more stealthy and dangerous - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/Konni.jpg","datePublished":"2022-02-01T06:21:29+00:00","description":"Threats grow as well as network security and many times we have seen endless examples such as the threat we will see today called Konni RAT...","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/Konni.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2022\/02\/Konni.jpg","width":800,"height":450},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/konni-rat-returns-more-stealthy-and-dangerous\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Konni RAT returns more stealthy and dangerous"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4009","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=4009"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4009\/revisions"}],"predecessor-version":[{"id":4011,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/4009\/revisions\/4011"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/4010"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=4009"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=4009"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=4009"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}