Konni - Remote Access Trojan
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Konni is predominantly delivered by spam email with macro enabled documents.
In the early stages of the malware, it acted as an information stealer and didn't gain remote administration capability until further into its lifecycle. The latest version is split across two binaries; conhote.dll and winnit.exe.
Konni is capable of but not limited to the following; uploading, downloading and deleting documents, taking screenshots and executing commands directly on the infected system.
When the malware connects with the Command and Control (C2) server, a wealth of information is gathered from the system and sent.
Remediation steps
Last edited: 17 February 2020 11:33 am