A recent cyber campaign has emerged, specifically targeting individuals and organizations involved with Ukraine by using document-themed Windows shortcuts to deploy a malware downloader known as VelvetCake. The operation, identified as Operation Conflict Compass by SOCRadar analysts, appears to be gathering political and military intelligence related to the ongoing conflict. The attackers are believed to distribute these threats through targeted emails containing ZIP attachments. These attachments include shortcut files disguised as PDFs with titles related to peace proposals, food prices, and researcher resumes. Once opened, these files execute malicious code while presenting a decoy document to the user.

The campaign has been linked to Konni, a known North Korea-linked espionage group, although the association is made with moderate confidence. The infrastructure underpinning the operation was observed as early as August 2026; however, specific victim details remain unverified. The malware employed in this campaign is capable of collecting system details, capturing screenshots, and exfiltrating files from infected devices. This tactic is consistent with previous attacks by Konni and similar espionage groups.

Attackers have deployed these lures on platforms such as a South Korean hosting service and a Ukrainian apparel website. Upon execution, the shortcuts initiate PowerShell scripts to download additional components and display a decoy document. In some instances, a modified video meeting installer has been used to deliver the malware, although the exact method of delivery remains uncertain. The VelvetCake downloader, once installed, connects to an attacker-controlled server to retrieve and execute additional scripts, maintaining a stealthy and adaptable presence on the compromised system.

The campaign's method bears resemblance to Kimsuky attacks, utilizing malicious shortcuts to initiate longer infection chains. Recovered scripts have shown capabilities to assess installed security software, system settings, and network configurations, as well as to capture screenshots and send collected data to external servers. While this demonstrates the malware's collection capabilities, there is no definitive evidence that data theft occurred across all targeted organizations.

Organizations involved in sensitive Ukraine-related activities are advised to exercise caution with unexpected document archives and meeting installers. Verifying file types before opening attachments, monitoring for unusual scheduled tasks, and reviewing PowerShell activity can help identify and mitigate these threats.