{"id":10088,"date":"2026-01-23T10:03:41","date_gmt":"2026-01-23T10:03:41","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/23\/north-korean-hackers-adopted-ai-to-generate-malware-attacking-developers-and-engineering-teams\/"},"modified":"2026-01-23T10:03:41","modified_gmt":"2026-01-23T10:03:41","slug":"north-korean-hackers-adopted-ai-to-generate-malware-attacking-developers-and-engineering-teams","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/23\/north-korean-hackers-adopted-ai-to-generate-malware-attacking-developers-and-engineering-teams\/","title":{"rendered":"North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams"},"content":{"rendered":"<p>    North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>North Korea\u2013aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. <\/p>\n<p>Using AI-written PowerShell code, the group known as KONNI is delivering a stealthy backdoor that blends real project content with malicious scripts. <\/p>\n<p>This operation shows how fast threat actors are adopting AI tools to speed up development and hide their tracks.<\/p>\n<p>In the latest wave, KONNI is targeting developers and engineering teams working on blockchain and crypto projects across the Asia\u2011Pacific region, including Japan, Australia, and India. <\/p>\n<p>The attackers craft detailed requirement papers that look like real product briefs, describing trading bots, credential systems, and delivery roadmaps, then deliver them as PDF lures.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXlFJ7p6_HQKe6kagFFUskmvzhF4SNZPKcHp1h3g6ll02A3RiZv-d1rNtkFWjxof1i3F2tDGxs-t9GL_6SyoR6EgszJH31oGA-A4NSf_NetW-JSZenWcdKZSHYoP4EYGmz3B0S7DXfSH5FWsWGYD5_rCycqSCmYSqUYvO8bINMuRGjxpWf-dxWddOXBqg\/s16000\/Blockchain%2520themed%2520lures%2520used%2520in%2520this%2520campaign%2520%28Source%2520-%2520Check%2520Point%29.webp?ssl=1\" alt=\"Blockchain themed lures used in this campaign (Source - Check Point) \"><figcaption class=\"wp-element-caption\">Blockchain themed lures used in this campaign (Source \u2013 Check Point) <\/figcaption><\/figure>\n<\/div>\n<p>These documents are designed to win the trust of technical staff and draw them into opening attached shortcut files that silently start the infection chain.<\/p>\n<p>Check Point researchers <a href=\"https:\/\/research.checkpoint.com\/2026\/konni-targets-developers-with-ai-malware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the activity as part of the long\u2011running KONNI cluster and noted that the payload is an AI\u2011generated PowerShell backdoor with extensive comments and clean structure. <\/p>\n<p>This backdoor does more than open a remote door; it gathers hardware details, checks for <a href=\"https:\/\/cybersecuritynews.com\/data-protection-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">debugging tools<\/a>, and ensures only one copy runs at a time, all while maintaining a professional, developer\u2011style layout.<\/p>\n<p>For victim organizations, the risk goes far beyond a single compromised workstation. By targeting developers who hold access to repositories, cloud consoles, and signing keys, KONNI can pivot from one infected endpoint into entire build pipelines or production systems.<\/p>\n<h2 class=\"wp-block-heading\" id=\"infection-chain-and-persistence-tactics\"><strong>Infection Chain and Persistence Tactics<\/strong><\/h2>\n<p>The attack begins when a target opens the ZIP archive and double\u2011clicks a Windows shortcut file that sits next to the PDF lure. <\/p>\n<p>That shortcut runs an embedded <a href=\"https:\/\/cybersecuritynews.com\/windows-powershell-0-day-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> loader, which quietly drops a second lure document and a compressed CAB archive.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhGT2oq7yX2fc5jVE2ZolLn_x6NJgeB8iQBAyxyh8Vcd9k_8wxELyWYeWA6xOiSraUJwvq9GkBR56NsXzeO3isUP2AUraRRRmvGPgNLWu3teHPZv9MGaNEdCM8agUFl-h8zIU1XM7_nTs_zT-hg18C4_6i7SEoN-v1MhUI5y4zuQwQnivo1dohOQe_PErI\/s16000\/Infection%2520Chain%2520%28Source%2520-%2520Check%2520Point%29.webp?ssl=1\" alt=\"Infection Chain (Source - Check Point)\"><figcaption class=\"wp-element-caption\">Infection Chain (Source \u2013 Check Point)<\/figcaption><\/figure>\n<\/div>\n<p>From there, batch files unpacked from the CAB archive move the backdoor into a hidden ProgramData folder and create a scheduled task that mimics a OneDrive startup entry. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgqVIBsuLcjv7xx95vNOJkBZeQgfersFkdlXsVFGbwHD2SY_1Qthnt1GtC8EEDd3C61pRYF40xlJsNn0ZIg09xbRdXL8ZLdNHrxypMkn9efYzfF8LsD6StggdIyjfLF9XV2WKPcudbbi6I-kuVWDc14fsxv_Lk0vXWmz6XHAzSjof0LXzBDZzoYMscJe3Y\/s16000\/Privilege-Based%2520Execution%2520Flow%2520%28Source%2520-%2520Check%2520Point%29.webp?ssl=1\" alt=\"Privilege-Based Execution Flow (Source - Check Point)\"><figcaption class=\"wp-element-caption\">Privilege-Based Execution Flow (Source \u2013 Check Point)<\/figcaption><\/figure>\n<\/div>\n<p>This task runs every hour, decrypts the PowerShell payload from disk using a simple XOR key, and executes it directly in memory, keeping the core <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">malware<\/a> file\u2011less during runtime and making incident response far more difficult.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-adopted-ai-to-generate-malware\/\">North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/north-korean-hackers-adopted-ai-to-generate-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams North Korea\u2013aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. Using AI-written PowerShell code, the group known as KONNI is delivering a stealthy backdoor that blends real project content with malicious scripts. This operation [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10088","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10088"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10088"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10088\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}