Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Opal Sleet

Also known as: OSMIUM, Konni, Vedalia

Description

Konni is a threat actor associated with APT37, a North Korean cyber crime group. They have been active since 2012 and are known for their cyber-espionage activities. Konni has targeted various sectors, including education, government, business organizations, and the cryptocurrency industry. They have exploited vulnerabilities such as CVE-2023-38831 and have used malware like KonniRAT to gain control of victim hosts and steal important information.

AI Analysis

· 1 week ago

Executive Summary

Opal Sleet, also known as OSMIUM, Konni, or Vedalia, is a North Korean-associated cyber threat actor linked to APT37, known for cyber-espionage activities since 2012. The group targets sectors including education, government, business, and cryptocurrency, leveraging tools like KonniRAT malware and exploiting vulnerabilities such as CVE-2023-38831 to compromise systems.

Goals & Targeting

Opal Sleet’s strategic objectives likely align with broader North Korean interests in intelligence gathering and disruption of targeted industries. The group's focus on sectors like cryptocurrency, education, and government suggests a desire to gather sensitive information that could be used for political or economic advantage. Their targeting of businesses may indicate an intent to disrupt operations or gain competitive intelligence. Victims are typically organizations and individuals with access to critical data, making them prime targets for espionage.

Enhanced Description

Opal Sleet is a sophisticated threat actor suspected to be part of APT37, a North Korean cyber espionage group. They have been active since at least 2012 and are known for their targeted attacks against various sectors, including education, government, business organizations, and the cryptocurrency industry. Their primary focus appears to be on stealing sensitive information from both private and public sector entities, likely for intelligence gathering or financial gain. Opal Sleet has demonstrated a preference for specific attack vectors, including vulnerability exploitation and malware deployment. The group's use of tools like KonniRAT highlights their capability to maintain persistent access to compromised systems, enabling them to steal data over extended periods. Their activities underscore the growing sophistication of cyber-espionage operations attributed to North Korean actors.

Key Capabilities

  • Exploitation of known vulnerabilities (e.g., CVE-2023-38831)
  • Deployment of custom malware (KonniRAT)
  • Leverage spear-phishing campaigns
  • Persistent access to compromised systems

MITRE ATT&CK Tactics

Espionage
Adversary-in-the-Cloud

Software / Tooling

KonniRAT
Spear-phishing tools
Exploitation frameworks

Campaigns & Victims

Opal Sleet’s campaigns exhibit a focus on long-term data collection and espionage. They often target high-value assets within critical sectors, suggesting an intent to gather sensitive information over extended periods. Their operational tempo appears strategic, with patient attacks designed to avoid detection until the desired information is obtained. Notable operations include campaigns against cryptocurrency exchanges and educational institutions, likely aiming to窃取 financial data or disrupt operations.

IOC Patterns

  • Spear-phishing emails targeting specific sectors
  • Exploitation of CVE-2023-38831 (if applicable)
  • Malware deployment via KonniRAT

Recommended Actions

  • Implement strict email filtering to prevent spear-phishing campaigns.
  • Conduct regular vulnerability scanning and patching exercises.
  • Monitor for signs of persistent malware activity, particularly within targeted sectors.
  • Educate employees about phishing tactics and suspicious emails.

Suggested Tags

APT
cyber-espionage
North Korea
cryptocurrency

Confidence Assessment

Moderate confidence in Opal Sleet's characterization as a North Korean-linked threat actor. While there is substantial evidence linking them to APT37 and known activities, certain aspects such as exact motivations or campaign details remain speculative due to limited open-source reporting.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Financial Targeting
Backdoor / C2
Government Targeting
cyber-espionage
North Korea
cryptocurrency

Details

Type
Unknown
Country of Origin
K
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.