216.73.216.6

Operation Poseidon: Spear-Phishing Attacks Abusing Google Ads Redirection Mechanisms

· Published 18/01/2026 18:38 · Modified 19/01/2026 09:30

Export JSON

Essential information

Published
18/01/2026 18:38
Modified
19/01/2026 09:30
Tags
2026-01-18 autoit autoitrat endrat financial impersonation google ads north korean human rights redirection spear-phishing wordpress
Related entities
1 observables, 1 intrusion sets (apt), 18 techniques (mitre), 2 malware, 19 others

Description

Operation Poseidon is a sophisticated campaign attributed to the Konni APT group. The attackers exploit mechanisms to bypass security filters and user awareness. They compromise poorly secured sites for malware distribution and C2 infrastructure. The campaign uses social engineering tactics, impersonating organizations and financial institutions. Malware is delivered through LNK files disguised as PDF documents, executing scripts that load variants. The attackers employ advanced evasion techniques, including email content padding and abuse of legitimate advertising URLs. The campaign demonstrates evolving tactics and infrastructure reuse consistent with previous Konni activities.

External references