Fake PDFs Deliver VelvetCake Malware in Operation Conflict Compass Targeting Ukraine
A new campaign dubbed Operation Conflict Compass uses disguised PDF shortcut files to deliver the VelvetCake malware downloader, likely aiming to gather intelligence on Ukraine.

A newly documented campaign, identified as Operation Conflict Compass, is targeting individuals and organizations focused on Ukraine by employing disguised Windows shortcut files that appear as PDF documents to deliver a malware downloader named VelvetCake. The primary objective of this operation appears to be the acquisition of political and military intelligence related to the ongoing conflict.
Attackers are reportedly distributing targeted emails containing ZIP attachments. These archives hold shortcut files, also known as LNK files, which are designed to mimic legitimate PDF documents. The lures used include topics such as peace proposals between Russia and Ukraine, rising food prices linked to the Strait of Hormuz, and researcher resumes. The attackers also utilize modified video meeting installers as an alternative infection vector. SOCRadar analysts, who identified the activity, associate it with the North Korea-linked Konni espionage group with moderate confidence.
The infection chain begins when a target opens a malicious shortcut file. This action triggers a PowerShell script that fetches additional components and displays a decoy document to mask the malicious activity. The script then establishes a scheduled task, ensuring the malware's persistence by allowing it to run repeatedly. This method echoes previous Konni campaigns that have used disguised shortcuts, particularly those observed targeting entities in South Korea.
VelvetCake, the deployed malware downloader, is a lightweight tool designed to establish communication with an attacker-controlled server. From this server, it can retrieve and execute further scripts, and then exfiltrate any collected data. Its modular design allows operators to dynamically alter the malware's functionality without needing to replace the initial downloader, creating a flexible espionage platform.
One of the recovered follow-on scripts demonstrates significant data collection capabilities. It is designed to check for installed security software, gather system settings, analyze network configurations, list running processes, and identify recent files and available drives. Furthermore, it captures screenshots of the victim's desktop and transmits all collected information to an external server before deleting local copies of the evidence.
While the campaign has been active since at least August 2026, the exact number of confirmed victims remains unverified. However, the observed malware's capabilities indicate a strong potential for remote espionage and intelligence gathering. The themes used in the lures suggest that the attackers are specifically targeting individuals involved in diplomacy, policy research, and non-governmental organizations working on Ukraine-related issues.
Organizations handling sensitive information related to Ukraine should exercise extreme caution with unexpected document archives and meeting installers. Verifying the true file type of attachments before opening, monitoring for unusual scheduled tasks, and scrutinizing PowerShell activity can help detect and prevent infections from this campaign. The use of familiar document themes to mask malicious intent is a tactic that has been effectively employed by groups like Konni in the past.