North Korean Konni hackers use AI-generated PowerShell malware to target blockchain engineers
North Korean hacking group Konni is deploying AI-generated PowerShell malware to attack blockchain developers and engineers, with activity observed in the Asia-Pacific region. The campaign uses Discord-delivered ZIP files carrying a PDF lure and malicious shortcuts to install a PowerShell backdoor that can access sensitive infrastructure, API keys, wallets, and digital assets. Researchers have linked this malware to previous Konni operations and note clear signs of AI-assisted code generation in its documentation and structure.