#ARTFULPIE

Malware/Tool

2020-02-14 • MAR-10271944-2.v1 – North Korean Trojan: ARTFULPIE

ARTFULPIE is a 32-bit Windows downloader and in-memory loader identified by U.S. government analysts as a North Korean Trojan associated with HIDDEN COBRA activity. The implant downloads a DLL from a hardcoded HTTP URL using an Internet Explorer 9-style user-agent string. It keeps the retrieved DLL in memory, manually maps it into its own address space, and executes it without first writing the payload to disk. This design gives ARTFULPIE a compact role as a delivery component for a follow-on Windows implant.

Tagged Reports

« Back