North Korean hacker group targets blockchain sector with AI-enhanced malware

A new cyber attack is targeting developers and engineering teams in the blockchain and cryptocurrency sector. The campaign, attributed to the North Korean group KONNI (also known as Opal Sleet, TA406, or Kimsuky), represents a concerning evolution in the use of artificial intelligence to create more sophisticated malicious tools.

Since October 2025, security researchers have detected a series of attacks primarily targeting Japan, Australia, and India, indicating an expansion of the group’s operations in the Asia-Pacific region. The attackers use a spear-phishing technique, sending ZIP files hosted on Discord that contain seemingly legitimate PDF documents but hide malicious links (LNK). When activated, these files install a PowerShell backdoor whose peculiarity is the use of obfuscation techniques generated through artificial intelligence, specifically large language models (LLMs), to evade detection.

The potential impact of this campaign is significant. Once compromised, victims’ development environments can lead to access to corporate infrastructure, credentials, digital wallets, and ultimately, the theft of cryptocurrency assets. Attackers can also gain remote access using remote management tools (RMM), creating a permanent bridge into compromised systems.

To protect themselves, blockchain companies should implement rigorous security practices, including multi-factor authentication, regular system updates, employee training on recognizing suspicious emails, and advanced security controls specifically designed to detect anomalous activities. It is also advisable to perform regular security scans and implement endpoint security solutions capable of detecting suspicious behaviors rather than relying solely on known malware signatures.

  • Key points to remember:
  • The North Korean group KONNI is targeting blockchain developers in Asia-Pacific with advanced attack techniques that leverage AI
  • The attacks begin with phishing emails containing seemingly innocuous files on Discord but lead to the installation of sophisticated backdoors
  • Protection requires a multi-layered approach: personnel training, robust authentication, and security tools capable of detecting anomalous behaviors in systems

Sources:
Security Affairs – “North Korea-linked KONNI uses AI to build stealthy malware tooling”
Bleeping Computer – “KONNI hackers target blockchain engineers with AI-built malware”
Check Point Research – “KONNI targets developers with AI malware”

Source: The Hacker News