North Korea-linked hacking group “Konni” launches ‘Poseidon’ operation in South Korea

korea / Paul Lee 특파원 / 2026-01-20 06:10:16

North Korean IT hacker. (Photo: SNS)

 

 

[Alpha Biz= Paul Lee] The North Korea-associated hacking group Konni has reportedly been targeting users in South Korea with a new spear-phishing campaign dubbed the “Poseidon Operation”, exploiting legitimate URLs from services like Google to bypass traditional security systems.

According to a threat intelligence report by Genians Security Center on January 19, Konni disguises malicious links as legitimate advertising URLs. Victims receive emails impersonating institutions such as the Financial Supervisory Service; clicking the links triggers downloads of malware. The attackers mimic Google’s ad click-tracking system, making it difficult for security solutions to detect the malicious URLs. Malicious files analyzed contained the string “Poseidon-Attack,” suggesting that the campaign is systematically managed under the project name “Poseidon.”

The group has also attempted attacks via Google’s device location feature, Find Hub, targeting users of government and financial services. After stealing Google account credentials, the hackers could remotely delete data if the device was not nearby, causing secondary damage.

Experts warn that most recent cyberattacks in South Korea are delivered through email links and advise users to avoid entering sensitive information unnecessarily.

 

 

알파경제 Paul Lee 특파원(hoondork1977@alphabiz.co.kr)

주요기사

Samsung, Hyundai, LG Chiefs Depart to Join Presidential Economic Delegation to India and Vietnam
South Korea Urges U.S. to Exclude It from Section 301 Action, Rejecting Claims of Overcapacity and Forced Labor
South Korea Slips to No.3 in APAC HQ Preference as Firms Cite Labor Rigidity, Regulatory Burden
Korea to Provide $2.5 Million in Humanitarian Aid to Iran and Lebanon
South Korea Boosts EV Subsidy Budget in Supplementary Spending Plan
뉴스댓글 >

건강이 보이는 대표 K Medical 뉴스

SNS