#ARTFULPIE
Malware/Tool
2020-02-14 • MAR-10271944-2.v1 – North Korean Trojan: ARTFULPIE
ARTFULPIE is a 32-bit Windows downloader and in-memory loader identified by U.S. government analysts as a North Korean Trojan associated with HIDDEN COBRA activity. The implant downloads a DLL from a hardcoded HTTP URL using an Internet Explorer 9-style user-agent string. It keeps the retrieved DLL in memory, manually maps it into its own address space, and executes it without first writing the payload to disk. This design gives ARTFULPIE a compact role as a delivery component for a follow-on Windows implant.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days