North Korean hackers hijack Google’s Find Hub to locate and delete target devices


  • KONNI hackers use KakaoTalk to deliver malware and harvest account information from victims
  • Attackers exploit Google Find Hub to remotely wipe Android devices and avoid registration
  • Compromised PCs spread malware to contacts, while mobile devices are repeatedly reset to factory settings

North Korean threat actors with ties to the government were seen resetting target Android devices to factory settings to cover their tracks.

Genians researchers said they saw these attacks in the wild, primarily targeting individuals in South Korea, carried out by a group called KONNI (named after a remote access tool it uses)

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top